CISO Strategy
What the CISO Should Do to Help the Board Make Informed Decisions Around Security and Risk
- Develop and communicate a security mission statement rooted in business enablement
- Determine your risk appetite and document your risk tolerance in layman’s terms
- Choose a security framework and map initiatives to that framework
- Establish unbreakable rules around security responsibility and information sharing
- Keep the board updated on security trends and be prepared to discuss specifics, such as how the organization is responding to a specific threat drawing headlines
What the Board Should Do to Support a Culture of Security Awareness and Accountability
- Approach and understand cybersecurity as an enterprise-wide risk issue
- Learn the legal implications of cyber risks
- Access cybersecurity expertise by giving cyber risk discussions adequate time on the board meeting agenda
- Set the expectation that management will establish an enterprise-wide risk management framework with adequate staffing and budget
- Discuss cyber risks from the perspective of identifying which risks to avoid, mitigate, accept, or transfer through insurance, as well as specific plans associated with each