'To be an effective CISO, management skills now trump technology skills,’ expert says
The function of information security is splitting into two, with security technology implementation moving back into the IT department and the administration of information security becoming a management issue.
So says Eddie Zeitler, executive director of ISC2, an organization that issues Certified Information Systems Security Professional (CISSP) as well as a number of other security-related certifications. Zeitler gave the opening address at ISC2’s 2007 SecureAmericas conference being held near Washington, D.C., this week. During his talk he cited data from an ISF/ISC2 joint study, an ISC2/IDC joint study, and observations made by the SANS Institute.
The do’s and don’ts of an effective CISO
With this splintering, the role of the CISO – which he defines as the manager of information security – is changing.
“You need a solid grounding in technology to be a CISO … but to be an effective CISO, management skills now trump technology skills,” says Zeitler. “The role of the first-line security manager is moving back into IT … which is where it should be. But the oversight, policy making, [establishing] corporate programs, that’s moved more into management.”
Along with the new emphasis, however, is a shifting of accountability for IT security out of the IT department and up the corporate ladder to the CISO and even the CEO, he says.
Zeitler, who held a number of executive security positions at organizations including Charles Schwab before joining ISC2 last year, said CISOs who recognize that technology is the enabler of security, but not the solution, will prosper as the CISO’s management skills become more important than technical chops.
“Many of the security managers who are prospering [view] IT as an enabler for security but realize it doesn’t provide all that is needed” to secure an organization, Zeitler says.
Other factors of CISO success include documenting risk-reduction accomplishments, helping to effectively merge security and operations groups, and reinforcing security as a valued service to the company. Technical understanding and competence are also important, but perhaps not as much as it used to be.
“Technical people — the really good ones, typically – don’t have people skills, and that’s what all these interfaces require between business units and the technicians doing the job,” he continues. The CISSP program has a management concentration, but Zeitler also recommends taking financial and management courses outside of the program.
“Soft skills are the next thing security professionals need to get,” says Jim Litchko, president of the Litchko & Associates consulting firm, during a session at the conference about furthering careers in the security profession. “Now that you have your CISSP you’ve got the technical side down,” it’s time to focus on planning, communications, management, even sales skills to thrive as a CISO, he says.
During his talk, Zeitler profiled the typical CISO today, based on a survey done by ISC2 last year that had 4,000 respondents. According to this study, 66% of CISOs work for organizations that employ over 1,000 people, 54% of companies that have CISOs garner over $100 million in annual revenue, 13% of CISOs are women, the average number of years of experience in the profession is 8.7, 37% of CISOs have master’s degrees, and the average annual salary for a CISO is $81,000.




