The Circle of Cybersecurity: Leaders to Managers
A recent post of mine, The Circle of Cybersecurity, was a bit dense so I am expanding pieces of it in separate posts.
This post examines the first downward arrow, what flows from Leaders to Managers. That arrow is labelled "Policies" but that is a bit of shorthand for the many related kinds of information that travel that path.
In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF.
Priorities
In such a framework the first thing that leaders have to do is bless a list of digital assets to be protected. The managers may well provide a super set of all possible candidates, but the leaders need to impose priority on that super set. Almost no organization can protect every possible digital asset all the time.
Resources
Once the digital asset list is set for the time period--usually a year--then the organization has to budget for the people and equipment and support required to protect those digital assets. Leadership will probably require significant input from Managers to do this, but it is important for Leadership to exercise its authority and its oversight: the buck stops with Leadership. They sign off on the budgets and they are responsible for ensuring that there was value for money and time.
Policies
Often overlooked in this process are the value judgments needed by Managers to translate policies into procedures. In order for the Managers and CSEs to make good choices in implementation they need clear and useful principles from which to proceed. This sounds terribly abstract but it is not. I once saw a manager tell a CSE to "air gap" (meaning "unplug from the network") a device because the manager could not figure out how to apply the simple "protect all networked devices" edict to the much-needed but inflexibly configured photocopier/scanner/printer before her. There needs to be a way for Managers to resolve these issues. Some require face-to-face meetings, some require email exchanges but these interactions need to be relatively rare in order to be practical. Good policies both limit the need for exceptions and ensure a safe environment in which to raise the exceptions that must be discussed.
Communication & Culture
Cybersecurity cannot escape issues of communication and organizational behavior because cybersecurity rests largely on human beings and their daily decisions and actions. Leaders have responsibility in this process which should not be delegated "to IT" or "to the CS group." There are senior management functions required. If you don't do your job, someone else will have to your job for you.
Ensuring that your leaders are well-equipped to do their part in your CSP is hard. We can help. Ask us how.
Comments
Post a Comment