Caught in the crosshairs of “Leadership” and “Information Technology”, Information Security professionals are increasingly tapped to operate as business executives. This often puts them on a career path they did not expect, in a field not yet clearly defined. IT training does not usually includemanagerial skills such as leadership, team-building, communication, risk assessment, and corporate business savvy, needed by CISOs. Yet a lack in any of these areas can short circuit a career in information security.
CISO Leadership: Essential Principles for Success captures years of hard knocks, success stories, and yes, failures. This is not a how-to book or a collection of technical data. It does not cover products or technology or provide a recapitulation of the common body of knowledge. The book delineates information needed by security leaders and includes from-the-trenches advice on how to have a successful career in the field.
With a stellar panel of contributors including William H. Murray, Harry Demaio, James Christiansen, Randy Sanovic, Mike Corby, Howard Schmidt, and other thought leaders, the book brings together the collective experience of trail blazers. The authors have learned through experience—been there, done that, have the t-shirt—and yes, the scars. A glance through the contents demonstrates the breadth and depth of coverage, not only in topics included but also in expertise provided by the chapter authors. They are the pioneers, who, while initially making it up as they went along, now provide the next generation of information security professionals with a guide to success.
Table of Contents
A LEADERSHIP DISCONNECT
What You Told Us: A CISO Survey, T. Fitzgerald
A LEADERSHIP MANDATE
Who Companies Really Want to HIRE: How to Advance Your
Career and Have Great Success, J. Brocaglia
The Evolving Information Security Landscape, W.H. Murray
Business Drivers for Information Security, H. DeMaio
Security as a Business Function, P. Browne and S.R. Katz
Security Leadership, M.J. Corby and V.M. Carr
The Public Sector CISO: Life In The Fishbowl, L. McNulty
A LEADERSHIP EVOLUTION
A CISO Introspection, H.A. Schmidt
How Savvy Are You: Can You Get What You Want? B. Lee
Why and How Assessment of Organization Culture Should Shape Security Strategies, D. Saracco
Selling Information Security, J.S. Christiansen
The Importance of an IT Security Strategy, R. Sanovic
Extending The Enterprise’s Governance Program To Information Risks, R. Moulton and R. Coles
Building Management Commitment through Security Councils, T. Fitzgerald
Measuring Security, W.H. Murray
Privacy, Ethics, and Business, R. Herold
Leading Th rough a Crisis: How Not to Conduct a Security Investigation, M.D. Rasch
Security Pitfalls, T. Fitzgerald
Security Leader Horizon Issues: What the Future Holds, S. Skolochenko
"Contemporary information security is a relatively new specialty that continues to evolve. Even newer is the job title "chief information security officer." As a result, those who don the CISO mantle do so without an established playbook.
In CISO Leadership: Essential Principles for Success, a number of experienced and highly successful information security practitioners share their collective experiencesâ€”including mistakes. They provide valuable advice for those aspiring to become information security leaders.
A common theme throughout the book's 19 chapters is the idea that information security is about more than simply amassing technical knowledge. Rather, it is the combined set of skills that include leadership, team building, communication, risk assessment, and corporate business savvy. Lack of these skills has often resulted in a CISO's premature termination.
The book is divided into three sections all centered on the issue of leadership. Part I is titled "A Leadership Disconnect," while Part II "Leadership Mandate" features chapters on fundamental topics, such as career advancement, security as a business function, business drivers, and more. Part III, "Leadership Evolution," covers business savvy, organizational culture, selling security, and more.
For those with a forward career path in information security, CISO Leadership is a valuable guidebook. The authors' "war stories" can help you avoid the bumps as you go down that road. The breadth and depth of the experience of the authors makes this a unique book that you can use to further your information security career."
—Ben Rothke, Security Management