WEEK 1 Flashcards

POWERPOINTS

1
Q

What is the role of the CISO?

A
  • Security Policy
  • Business Enablement
  • Compliance
  • Protect Information Assets -
  • Protect Corporate Secrets
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Challenges of the CISO

A
  • Budget
  • Value Definition
  • Control of Resources
  • Technical Nature of Position
  • Interact with C Suite,Board of Directors
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Criteria for deciding where to place the CISO

A
  • OrganizationalMaturity
  • BusinessDomain
  • SkillAlignment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Criteria:

Organizational Maturity

A
  • How experienced is the organization in dealing with the types of risk that threaten lines of business?
  • Does it build operational resilience to disasters, disruptions, have contingency plans to recover?
  • Does it practice responding?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Criteria: Business Domain

A
  • Nature of external environment
  • Highly regulated?
  • Market segment
  • Security?
  • Operational threats?
  • Highly technical?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Criteria:

Skill Alignment

A
  • Info Security skillsets relative to rest of organization
  • Where does risk management responsibility lie?
  • Appropriate balance between technical and business acumen
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Less Mature organizations require more effort and focus by CISO
WHO DO THEY REPOT TO?

A

Prefer CISO reports to COO as extension of Operational Arm of organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

More mature organizations can rely on embedded personnel and resources more often
WHO DOES THE CISO REPROT TO?

A

CISO reporting to CIO or CFO is more common here (they own the risk), though less effective in ability to force change

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Three factors THAT influence BUSINESS criterion ?

A
  • Regulatory Environment
  • Threat Environment
  • Technical Environment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the threat to your organization?

A
  1. Do you have defined threat vectors?
  2. Is your organization political/activist in nature?
  3. Do you store/process valuable data?

report to CEO/COO for high threat environments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How is the CISO role similar to the CTO or CIO?

A
  • Need to centralize technology management
  • Need to improve efficiency and efficacy
  • Manage risk of complexity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How is the CISO role different from the CTO or CIO?

A
  • As a risk manager, the CISO requires significant business acumen
  • Organizational efforts may require influence beyond technology department
  • Bring order from chaos across all functional groups
  • Must be authorized to initiate/direct emergency actions to respond to security events (especially in high compliance environments)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Three models for a CISO

A
  1. Technical IT-Focused CISO(traditional)
    • CISO report to IT (CIO or CTO)
    • Views security from Technical perspective
  2. Empowered CISO (growing approach)
    • CISO report to CEO or CFO
    • Views cybersecurity in broader, risk-focused terms
  3. Non-CISO CISO (new security role emerging)
    • designated security officer
    • regulatory and/or industry requirements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CISO provides guidance and expertise on ?

A
  • Cybersecurity practices, procedures, metrics
  • Data and asset classification
  • Vigilance and monitoring of cybersecurity activities and trends
  • Oversight of auditing and governance practices
  • Incident response
  • Security policy design
  • Security services implementation
  • Security training
  • Holistic Risk Management and Assessment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Role as CISO : Responsibility?

A
  • protect organizations assets
  • Data
  • Networks
  • Applications • People
  • Provide key security services
  • Not interfere with ability to conduct business
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Do you have the authority you need?

A
  • Do I have the authority to act in an emergency?
  • Do I have the authority to manage the cybersecurity suite?
  • Do I control my budget?
  • Do I select devices/applications used?
  • Do I have authority to change and create policy?
  • Am I a member of the IT Leadership Team?
  • Am I allowed to present cybersecurity issues directly to executive management?