-
Book Overview & Buying
-
Table Of Contents
Executive's Cybersecurity Program Handbook
By :
Your first 90 days as a new manager, director, or CSO can be an exciting yet intimidating time. How will you get a budget for your program? How does executive management see information security? How will you develop a cybersecurity strategy? There are so many questions, yet few initial answers. Many come into the position and begin throwing technology at the problem, drowning in the Fog of More.
Remember, a security program is more than just technology; it also consists of people and processes. The key to getting started during your first 90 days is to understand the business, its processes, and how key stakeholders see the alignment of information technology and security to the business. Begin developing the department’s mission and vision statements and evangelize them throughout. Get others involved when creating these documents to gather their input and see what is important to them too.
As you have learned in this chapter, your first 90 days is also a time for creating new relationships with your coworkers. Relationships matter when it comes to information technology and security – make sure they are a priority. Eventually, you will have to work with colleagues from all different aspects of the business. Coworkers from finance, human resources, manufacturing, and other departments will have to be incorporated into your processes. Business continuity, incident response, and risk management are not information technology problems; they are business problems. As such, personnel from these departments need to be involved too.
We have now set the initial structure for the cybersecurity department, what is important, and why. In the next chapter, we will discuss the importance of a cybersecurity framework and its overall impact on the department and the organization. These two chapters help set the foundation you can begin to build a strategy on moving forward.