top 10 ways to lead a high performing information security program (30012012) low res

9
A White Paper By Todd Bell, CISSP, PMP, QSA, MPM, MBA February 2012 EC-Council www.eccouncil.org/ciso uncil www. Top 10 Ways to Lead a High-Performing Information Security Program

Upload: connecttech-llc

Post on 05-Dec-2014

388 views

Category:

Documents


0 download

DESCRIPTION

Today’s threat landscape requires CISOs to develop and implement a high-performing information security (IS) program. One of the biggest challenges is not letting the torrent of corporate issues interfere with the overall effectiveness of the IT security team. The Top 10 List is developed on the basis of the “Implementing a High-Performing Information Security Program” panel discussion that took place at the EC-Council CISO Executive Summit in December 2011. This list is designed to help CISOs avoid the daily traps that distract their teams from carrying out tactical and strategic functions.

TRANSCRIPT

Page 1: Top 10 Ways To Lead A High Performing Information Security Program (30012012)  Low Res

A White Paper

By Todd Bell, CISSP, PMP, QSA, MPM, MBA

F e b r u a r y   2 0 1 2

EC-Council www.eccouncil.org/cisoEC-Council www.eccouncil.org/ciso

Top 10 Ways to Lead a

High-Performing Information Security Program

Page 2: Top 10 Ways To Lead A High Performing Information Security Program (30012012)  Low Res

Top 10 Ways to Lead a

High-Performing Information Security Program

Today’s  threat  landscape  requires  CISOs  to  develop  and  implement  a  high-­‐performing  infor-­‐

-­‐

www.eccouncil.org/ciso

1

Copyright  ©  EC-­‐Council,  2012.  All  Rights  Reserved

01 Work smarter not harder

-­‐

Page 3: Top 10 Ways To Lead A High Performing Information Security Program (30012012)  Low Res

www.eccouncil.org/ciso

2

Copyright  ©  EC-­‐Council,  2012.  All  Rights  Reserved

02 Know your political landscape

03 Throttle back with adding more

tools to an IT Security program

Page 4: Top 10 Ways To Lead A High Performing Information Security Program (30012012)  Low Res

www.eccouncil.org/ciso

3

Copyright  ©  EC-­‐Council,  2012.  All  Rights  Reserved

04 Don’t stagger compliance

initiatives throughout the year

-­‐

-­‐

-­‐

-­‐

-­‐

05 Partner with trusted advisors

-­‐

-­‐

-­‐

-­‐

-­‐

-­‐

-­‐

-­‐

Page 5: Top 10 Ways To Lead A High Performing Information Security Program (30012012)  Low Res

www.eccouncil.org/ciso

4

Copyright  ©  EC-­‐Council,  2012.  All  Rights  Reserved

06 Problem of the day

07 Use a compliance

management tool

-­‐

-­‐

-­‐

-­‐

Page 6: Top 10 Ways To Lead A High Performing Information Security Program (30012012)  Low Res

www.eccouncil.org/ciso

5

Copyright  ©  EC-­‐Council,  2012.  All  Rights  Reserved

08 Everyone needs more staff

09 Build your executive

“political” capital

-­‐

-­‐

-­‐

-­‐

-­‐

-­‐

-­‐

Page 7: Top 10 Ways To Lead A High Performing Information Security Program (30012012)  Low Res

www.eccouncil.org/ciso

6

Copyright  ©  EC-­‐Council,  2012.  All  Rights  Reserved

10 Perception is reality and

change is a solutionIt  is  easy  for  anyone  to  get  into  the  mode  of  “this  is  the  way  it  always  has  

about  some  of  your  issues  and  challenges  and  chances  are  they  will  be  

-­‐

Page 8: Top 10 Ways To Lead A High Performing Information Security Program (30012012)  Low Res

www.eccouncil.org/ciso

7

Copyright  ©  EC-­‐Council,  2012.  All  Rights  Reserved

About the Author

Todd Bell,

Page 9: Top 10 Ways To Lead A High Performing Information Security Program (30012012)  Low Res

www.eccouncil.org/ciso

8

Copyright  ©  EC-­‐Council,  2012.  All  Rights  Reserved

-­‐

-­‐