Preparing the CISO - C|CISO Meetup Series


Details
Preparing the CISO - C|CISO - Meetup Series
The C|CISO Meetup series reinforces the importance to the CISO of building relationships within the organization (especially with the board) in delivering security, especially for CISOs coming from a technical background. How the C|CISO programme can help in preparing you for this shift of emphasis.
In the first of the C|CISO Meetup series we will look at the Certified Chief Information Security Officer (C|CISO) programme and cover the following topics;
- Information Security Management Program
- Defining an Information Security Governance Program
- Regulatory and Legal Compliance
- Risk Management
- IS Management Controls and Auditing Management
Further C|CISO Meetup sessions will cover additional topics and focus on how the CISO needs to build relationships and support for security as a common thread, as well as some of the pitfalls that come with the role of the CISO.
C|CISO Meetup Series #2
- Designing, deploying, and managing security controls
- Understanding security controls types and objectives
- Implementing control assurance frameworks
- Understanding the audit management process
C|CISO Meetup Series #3
- The role of the CISO
- Information Security Projects
- Integration of security requirements into other operational processes (change management, version control, disaster recovery, etc.)
C|CISO Meetup Series #4
- Access Controls
- Physical Security
- Disaster Recovery and Business Continuity Planning
- Network Security
- Threat and Vulnerability Management
- Application Security
- System Security
- Encryption
- Vulnerability Assessments and Penetration Testing
- Computer Forensics and Incident Response
C|CISO Meetup Series #5
- Security Strategic Planning
- Alignment with business goals and risk tolerance
- Security emerging trends
- Key Performance Indicators (KPI)
- Financial Planning
- Development of business cases for security
- Analyzing, forecasting, and developing a capital expense budget
- Analyzing, forecasting, and developing an operating expense budget
- Return on Investment (ROI) and cost-benefit analysis
- Vendor management
- Integrating security requirements into the contractual agreement and procurement process
- Taken together, these five Domains of the C|CISO program translate to a thoroughly
- knowledgeable, competent executive information security practitioner.
For CISO soft skills see our Human Skills for the Future Security Leader Meetup Recording.

Preparing the CISO - C|CISO Meetup Series