Council Post: The Evolving Role Of The CISO

General News

Summary

Most groups can figure out how to make something mostly functional — the cloud, containers, orchestration, security testing in builds and so on. The role must be a source of know-how that gets translated into the culture, process and technology everyone uses to get those functional things done without tipping the risk versus productivity balance the wrong way. To put that in practical terms, the CISO role can continue to include the traditional “make rules and do testing” duties. They must build bridges and continually consolidate knowledge from all the relevant subject matter experts to define what is and isn’t acceptable relative to code quality, security and resilience. The software security group can provide the data, but risk acceptors must start to “think globally and act locally.” Remember, everyone in the organization is getting things done; technology is working, services are being delivered and products are being sold.

Classifications

industries
No industries detected
applications
Engineering & Scientific

AskAI Classifications

Labels
Electronic Design Automation (EDA) Semiconductor Software Developer Tools

Linked Companies