Главная
Study mode:
on
1
THE ADVANCED COMPUTING SYSTEMS ASSOCIATION
2
Security Teams
3
Determine risk tolerance
4
Most boards lack cybersecurity expertise
5
Many CISOs don't know how to effectively engage the board
6
Gartner CISO Coalition
7
Purpose
8
In-depth interview field study
9
The 'CISO' title doesn't grant credibility
10
Credibility can be built through engagement
11
Don't wait to be called on
12
Tips
13
Negotiate access to the board
14
Understand what makes each board member tick
15
Build relationships with stakeholders
16
COO CIO CEO CFO HHR
17
Share information with board members
18
Pre-arm the CEO with information
19
How to communicate with the board?
20
Explain risk in context of the business
21
"They don't care about my vulnerability management project. They really don't." CISO
22
Don't use fear
23
Security 101
24
Set realistic expectations
25
The reason they didn't gain that is because they couldn't. They didn't speak the business language. ... They spoke the technical language and it just created a barrier that they couldn't speak at the…
26
The power of the board and CISO working together
27
Increase attention from C-suite
28
Back up the CISO
29
Take-aways
30
1. The CISO title isn't enough
31
2. Virtuous cycle of board engagement
32
Boards can become an immense resource for CISOS
Description:
Explore a 21-minute conference talk from USENIX Enigma 2022 that delves into the often-overlooked yet potentially most influential security team in an organization: the board of directors. Gain insights from Anthony Vance of Virginia Tech as he shares findings from in-depth interviews with board directors, CISOs, and senior-level consultants. Discover the challenges CISOs face when engaging with boards, learn strategies for gaining strategic importance in supporting and advising directors, and understand how to help boards realize their potential as a powerful security asset. Uncover valuable tips for CISOs, including negotiating board access, building relationships with stakeholders, and effectively communicating risk in business context. Examine the importance of speaking the board's language, setting realistic expectations, and leveraging the board's influence to increase C-suite attention and support for security initiatives.

The Security Team at the Top - The Board of Directors

USENIX Enigma Conference
Add to list