Skip Links

The do's and don'ts of an effective CISO

Network World
May 22, 2007 11:24 AM ET
  • Print

According to Eddie Zeitler, executive director of security certification organization ISC2, the role of the CISO is evolving to focus more on management and less on IT:

Traits of an effective CISO

* A decision maker (leader).

* Good understanding of business principles.

* Good understanding of the organization.

* Talks business language (a translator).

* Aligns security posture with business strategy.

* Sensitive to organization’s risk appetite.

* Willing to take responsibility.

* Gets fundamentals dealt with first.

* Talks risk.

 

Traits of an ineffective CISO

* Is an “island.”

* Is a “geek.”

* Has no understanding of how to tie security into the needs of the business.

* Has poor leadership/management/judgment skills.

* Is usually fire-fighting.

* Does not network with peers.

* Talks technology.

-- Cara Garretson


What it takes to be a great CISO

Read more about security in Network World's Security section.

  • Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?

Videos

rssRss Feed