
From the library
Bill Bonney, Gary Hayslip, Matt Stamper, 2017
In one paragraph
A comprehensive reference guide for Chief Information Security Officers, covering cybersecurity leadership, risk management, and strategic security planning in organizations.
Also tagged
Where this sits in the operating system
Systems Over Goals
Systems Over Goals
Systems Over Goals
Key insights
Three authors answer each question separately and disagree, which is more useful than a single confident method.
Security is presented as a business risk function rather than a technical one, so the artefacts are budgets, boards and reporting lines.
Its value is as a reference for the first ninety days in the role, not as a book to read through.
Recognise it early
The failure and the correction sit side by side deliberately. Read the left column asking whether any of it is already true of you.
Being seen as business blocker instead of enabler
Focusing on compliance checkboxes instead of risk reduction
Reactive security management instead of proactive prevention
Poor communication with business stakeholders
Centralizing security instead of building organizational capability
The same idea, argued differently
Ryan Daniel Moran
David Allen
John Warrillow
Sam Carpenter
The full breakdown
Before you close this
Naming the specific moment you will act roughly doubles the odds you do.
Reference
We use cookies to enhance your experience, analyze site traffic, and personalize content. You can manage your preferences or learn more in our Privacy Policy.