Late last week, President Obama outlined his plans to address U.S. cybersecurity risks. One of his immediate actions will be to appoint a cybersecurity coordinator reporting to the Office of the President who will work directly with the National Security Council (NSC)and other federal agencies to manage cybersecurity policy, legislation, and programs.
Some have suggested that a coordinator is the wrong position and that the federal government needs a Chief Information Security Officer (CISO) just as it has recently added a CIO and CTO. I completely disagree with this thesis. CISOs tend to focus on securing business processes with controls and technologies. Yes, these are important skills, but the federal cybersecurity coordinator should also be:
1. A Washington insider. President Obama's cybersecurity point person will have to work with State agencies, schmooze legislators, and dance around military and intelligence boundaries.
2. A strong communicator. The coordinator will need to communicate esoteric security concepts in pedestrian language with charisma and enthusiasm.
3. A business person. Working with the private sector is a big part of the job. The coordinator will have to bridge government agencies with the business community and understand how to play the carrot and stick.
Most CISOs I know simply don't have these skills. Let's hope the president chooses someone who does so we can make progress quickly.
Post new comment