Change, Conflict and Culture
We have many institutions either going through or coming out of a large amount of change. It seems like there’s always some new guidance, product, or...
A BISO (Business Information Security Officer) is an ombudsman for business lines across an institution. This person is responsible for representing the business requirements, controls, and perspectives of their respective areas. BISOs can have a tremendous impact on the success of the information security program by ensuring clear communication happens between the CISO and business lines. I think we can all agree in many instances there is little to no communication, leading to many missed opportunities, problems, and risks.
When I started programs from scratch or rebooted them, I have used a model similar to the BISO model with security committees. I tried to have an individual nominated from each business line to represent them on the committee. Their perspectives, questions, and concerns were invaluable to ensuring the effectiveness of the program and getting our message to the users in their area. Here are some examples:
So, should your institution have a BISO program? If you find you’re missing representation and insight from your business lines, I would greatly recommend it whether it goes by the name BISO or not. Also, it really doesn’t have any direct costs, just a piece of the group's time.
If you would like more information on how to expand your governance model to include BISOs, please contact us at support@bedelsecurity.com.
We have many institutions either going through or coming out of a large amount of change. It seems like there’s always some new guidance, product, or...
While the definition of a partner is fairly broad, its principles apply to a very broad spectrum of relationships. In the cybersecurity realm, this...
It’s easy to use the terms “Information Technology (IT)” and “Information Security (IS)” interchangeably. They are equally important but serve...