Загрузка...

The CISO — Chain of Command | Nat20 InfoSec Ep. 24

We met the cleric last episode. The coordinator, the translator, the one who keeps the party pointed at the same target.

Here's the question we didn't answer: who does the cleric answer to?

That decision — who the security function reports to, and how the team underneath is structured — is one of the biggest predictors of whether a security program actually has the authority to do its job.

In this episode:
- The CISO — the cleric at the organizational level, and what the role actually owns
- The reporting line fight: CISO under the CIO vs. a direct line to the CEO or board
- Centralized vs. federated vs. hybrid security team structures
- The vCISO — how smaller organizations get strategy without a full-time executive
- Why the org chart itself is a security control

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Nat20 InfoSec is an information security education series built for people who think in terms of kingdoms, adventuring parties, and campaigns. Arc 3 — The Adventuring Party — introduces the defenders: their roles, disciplines, and the structures that determine whether they have any authority at all.

The series is structured like a player's handbook. Every episode is a lesson. Every concept is a rule of the realm.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

#InfoSec #Cybersecurity #CISO #SecurityLeadership #TTRPG #Nat20InfoSec

Видео The CISO — Chain of Command | Nat20 InfoSec Ep. 24 канала Nat20 InfoSec
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять