Friday | 10 July, 2009
CSO
How to Prepare for a CISO Position
Rolf Moulton 28/09/2006 12:58:34

While you enhance your security and business skills, you can work within your own organization to prepare for a career transition. Here are some ideas from a panel discussion at the 2006 RSA North America conference about becoming a CISO:

Learn to collaborate with other departments to integrate and appreciate other roles. According to an Auburn University study, "Managerial Dimensions in Information Security: A Theoretical Model of Organizational Effectiveness", implementing information security programs requires exceptionally high levels of "task interdependence": Respondents said 62 percent of their daily tasks depended on the exchange of information or cooperation with others.

Take the value-added approach by learning how to align your responsibilities and accountability with each department's business goals. Look at the big picture - the goals and focus of the organization. Think in terms of the overall business, and know the impact you have on it and how what you do creates value for the organization. Communicating the value of information security will help in building a spirit of cooperation throughout the organization.

Develop your own circle of trust within your ­organization with representatives from each department to help promote mutual understanding, appreciation and teamwork. When more people agree with you, you gain credibility. Eventually, executives will learn about your group and recognize the value in consulting you.

Engage executives in conversation so they can get to know you and learn to trust you. These conversations should be succinct but meaningful, using business terms, not "geek speak" or acronyms. Determine how you can add value to their goals, then make your case as to why you should be consulted or included in a meeting.

Offer executive and user security-awareness training on security threats affecting home offices and present prevention techniques. Executives will see the difference you make to their home computers or networks, and that builds their trust in your ability to make recommendations for the business's networks.

Learn to balance opportunity risks. Many executives perceive security staff as inflexible, so they don't want to invite them to strategy meetings. Be flexible in balancing security risks with business processes that help the organization meet its goals.

So, would you like to be a CISO? Are you willing to step away from some of the technical aspects of information security? If the answer is yes, keep up to date with your technical knowledge and certifications, and learn business language and softer communication and presentation skills. Develop relationships with executives so they are aware of your knowledge and skills, will begin to trust you and will see you as a good choice for a C-level position.

Rolf Moulton is a CISSP-ISSMP, president and interim CEO of ISC2. He can be reached at rmoulton@isc2.org

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

LANPlanner | Ensuring High Performance WLAN Networks

Learn how the Motorola LANPlanner facilitates prompt and precise planning and the design and measurement of robust 802.11a/b/g/n networks. Download this paper now to discover how to take wireless network performance to the next level.

Sponsored Links