The Circle of Cybersecurity: Managers to Leaders
A recent post of mine, The Circle of Cybersecurity , was a bit dense so I am expanding pieces of it in separate posts. This post examines the upward arrow that flows from Mangers to Leaders. That arrow is labelled "Status" but that is a bit of shorthand for the related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Status Like "evidence," "status" is a concept we all think we understand until we need to define it. One of the big steps in implementing a good CSP is agreeing on the compromise that is status. There is always compromise because there are limits to what the evidence the Managers have been given and there are limits on what the Leaders can comprehend and absorb. One colleague of mine once joked that "boardroom reports...