None
EN
The ineffective CISO
[]
Open Source Security
I hear a lot of stories about how a CISO has to report to the board, or the CEO, or everyone in IT should report to the CISO, or some other crazy reporting structure to give the CISO the power they need to do the job. It’s important for an organization to be secure and if the CISO isn’t at the table for every decision, nothing will be secure because nobody else knows how security works. From what I’ve seen the reason there is talk like this is because in a lot of organizations the security team, and by extension the CISO, is so ineffective at driving change the only way to get it done is to get someone at the top of the company to demand everyone listens to the CISO, or else!