52

Build Cloud capabilities in InfoSec team

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Build Cloud capabilities in InfoSec team
Page 2: Build Cloud capabilities in InfoSec team

Build Cloud capabilities in InfoSec team

1

Page 3: Build Cloud capabilities in InfoSec team

Develop effective metrics for continuous improvement

2

Page 4: Build Cloud capabilities in InfoSec team

Reduce dependency on external consultants

3

Page 5: Build Cloud capabilities in InfoSec team

Build effective relationships with outsource partners

4

Page 6: Build Cloud capabilities in InfoSec team

Build security engineering capability in-house

5

Page 7: Build Cloud capabilities in InfoSec team

Improve detect, analyse, respond times

6

Page 8: Build Cloud capabilities in InfoSec team

Develop new security finance models to reflect shift in software OPEX spend

7

Page 9: Build Cloud capabilities in InfoSec team

Develop healthier relationships with infosec vendors

8

Page 10: Build Cloud capabilities in InfoSec team

Use emerging tech to help make infosec resources more accessible to the business

9

Page 11: Build Cloud capabilities in InfoSec team

Gain assurance that security products are secure and actually work

10

Page 12: Build Cloud capabilities in InfoSec team

Ensure appropriate regulatory compliance

11

Page 13: Build Cloud capabilities in InfoSec team

Obtain attention from the board

12

Page 14: Build Cloud capabilities in InfoSec team

Optimise cost and utilisation of technology for infosec

13

Page 15: Build Cloud capabilities in InfoSec team

Understand the security impact of digitization of our products and services

14

Page 16: Build Cloud capabilities in InfoSec team

Improve user experience of infosec services

15

Page 17: Build Cloud capabilities in InfoSec team

Review and assure supply chain

16

Page 18: Build Cloud capabilities in InfoSec team

Priorities specific to my business's sector

17

Page 19: Build Cloud capabilities in InfoSec team

Invest in the hard and soft skills of the infosec leadership team

18

Page 20: Build Cloud capabilities in InfoSec team

Better demonstrate value of infosec to the organisation

19

Page 21: Build Cloud capabilities in InfoSec team

Encourage better collaboration across the business

20

Page 22: Build Cloud capabilities in InfoSec team

Improve identity management and authentication

21

Page 23: Build Cloud capabilities in InfoSec team

Better visibility and assurance of supply chain security

22

Page 24: Build Cloud capabilities in InfoSec team

Promote diversity in the info/cyber security team

23

Page 25: Build Cloud capabilities in InfoSec team

Improve diversity in senior infosec roles

24

Page 26: Build Cloud capabilities in InfoSec team

Reduce operational security costs

25

Page 27: Build Cloud capabilities in InfoSec team

Adapt infosec models to new digital business models

26

Page 28: Build Cloud capabilities in InfoSec team

Introduce a Service Delivery model for infosec

27

Page 29: Build Cloud capabilities in InfoSec team

Introduce a new Governance, Risk and Compliance (GRC) platform

28

Page 30: Build Cloud capabilities in InfoSec team

Create new risk models to reflect move to IaaS, PaaS, and SaaS

29

Page 31: Build Cloud capabilities in InfoSec team

Understand infosec requirements for senior executives

30

Page 32: Build Cloud capabilities in InfoSec team

Develop and implement a new brand for infosec

31

Page 33: Build Cloud capabilities in InfoSec team

Improve infosec's engagement with agile projects

32

Page 34: Build Cloud capabilities in InfoSec team

Introduce a service-based infosec architecture

33

Page 35: Build Cloud capabilities in InfoSec team

Enable enterprise-wide visibility and monitoring

34

Page 36: Build Cloud capabilities in InfoSec team

Implement a zero-trust model

35

Page 37: Build Cloud capabilities in InfoSec team

New controls for PaaS and SaaS security

36

Page 38: Build Cloud capabilities in InfoSec team

Understand risk profiles of emerging technologies like AI and Distributed Ledgers

37

Page 39: Build Cloud capabilities in InfoSec team

Shepherd investment from multiple projects into infosec infrastructure

38

Page 40: Build Cloud capabilities in InfoSec team

Introduce a team of InfoSec champions to improve understanding across the business

39

Page 41: Build Cloud capabilities in InfoSec team

Protect legacy line of business systems from modern threats

40

Page 42: Build Cloud capabilities in InfoSec team

Develop programmes to develop infosec skills in the general workforce

41

Page 43: Build Cloud capabilities in InfoSec team

Explore opportunities from automation in improving infosec

42

Page 44: Build Cloud capabilities in InfoSec team

Make security decisions more evidence-based

43

Page 45: Build Cloud capabilities in InfoSec team

Minimize the amount of data stored in the organisation

44

Page 46: Build Cloud capabilities in InfoSec team

Find ways to pay down technical debt

45

Page 47: Build Cloud capabilities in InfoSec team

Support innovation activities in the organisation

46

Page 48: Build Cloud capabilities in InfoSec team

Manage org expectation of risk management versus speed of business and technology change

47

Page 49: Build Cloud capabilities in InfoSec team

Understand how to engage with startup businesses

48

Page 50: Build Cloud capabilities in InfoSec team

Influence organisational culture and culture change

49

Page 51: Build Cloud capabilities in InfoSec team

Explore technologies to monitor social presence of staff and customers

50

Page 52: Build Cloud capabilities in InfoSec team

CISO Priorities1st Edition, 2019by Matt Ballantine & Phil Huggins

licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.stamplondon.co.uk/cxopriorities