Five Questions You Should Be Asking About Your Cybersecurity Program
Ahh, springtime. I love it. The birds, the flowers, the warm sunshine, the BankDirector.com Risk Survey Report.
A BISO (Business Information Security Officer) is an ombudsman for business lines across an institution. This person is responsible for representing the business requirements, controls, and perspectives of their respective areas. BISOs can have a tremendous impact on the success of the information security program by ensuring clear communication happens between the CISO and business lines. I think we can all agree in many instances there is little to no communication, leading to many missed opportunities, problems, and risks.
When I started programs from scratch or rebooted them, I have used a model similar to the BISO model with security committees. I tried to have an individual nominated from each business line to represent them on the committee. Their perspectives, questions, and concerns were invaluable to ensuring the effectiveness of the program and getting our message to the users in their area. Here are some examples:
So, should your institution have a BISO program? If you find you’re missing representation and insight from your business lines, I would greatly recommend it whether it goes by the name BISO or not. Also, it really doesn’t have any direct costs, just a piece of the group's time.
If you would like more information on how to expand your governance model to include BISOs, please contact us at support@bedelsecurity.com.
Ahh, springtime. I love it. The birds, the flowers, the warm sunshine, the BankDirector.com Risk Survey Report.
A few weeks ago, in my life outside of cybersecurity, a person said to me: “You are always thinking three steps ahead of the rest of us”. I am not...
Being on the board of a financial institution is not easy. Board members are expected to not only be knowledgeable about the operational and...