Who In The World? Intro To Mapping Talent To Your CSP Stages
It is very tempting to assume that putting together a cybersecurity team is like assembling individual photos to create an intact image. Once again , assumptions are dangerous. Groups of people are not teams. It's very easy for managers to think that people in a group will behave like a team because you've all had lunch together or you're all Sagittariuses or something like that. Wrong. A team requires roles, shared responsibilities, rules, and enforcers. Maybe it's obvious but teams also need a mission. Your cybersecurity program is the mission. But as Brendan's discourses on the NIST CSF makes clear (e.g., here and here ), there are different parts of the mission. Different parts require different specializations. Formally put, there are six phases of the NIST CSF. We advise managers to not hire people to fill all size functions. Our talent assessment work with very effective leaders shows that even at the elite levels of cybersecurity leadership, different tale...