Os Papéis · Quem defende

Security leader

Escrito a partir de fontes publicadas

The top of the management arm, in security. The framework describes the work as establishing vision and direction for an organisation's cybersecurity operations and resources, with the authority to make decisions that reach the whole organisation, approve policy and engage stakeholders. The ladder below it runs manager, then director, then this — and each rung trades proximity to the work for reach across it.

Como é o dia

  • Setting direction, and holding it while the quarter argues with it.
  • Acquiring resources: budget, headcount, and the authority to require things of teams elsewhere.
  • Approving policy, and owning the consequences when it is applied to a business the policy inconveniences.
  • Advising senior management and the board, in terms of risk to the organisation rather than in terms of technology.
  • Communicating the value of the programme to stakeholders, which is the task the framework names and the one most easily deferred.

Pelo que responde

  • The organisation's security posture, including the parts owned by teams elsewhere.
  • The programme having a strategy that connects to the organisation's actual risks.
  • What the board is told, and whether it was accurate at the time.

Como é medido

  • Risk reduction, which resists measurement and is measured anyway.
  • Incidents and their consequences, which are visible and partly outside the role's control.
  • Audit and regulatory outcomes, and programme delivery against plan.

De quem recebe

The operations and response teams
What is happening, at the fidelity the tooling allows.
The business
Where it is going, which decides what has to be protected next.
Regulators, auditors and insurers
Obligations that arrive with dates attached.

A quem serve

The board and executive
Risk expressed in terms they can decide with.
The security teams
Direction, resources, and cover when a decision proves unpopular.
The rest of the organisation
Policy that can be followed by people whose job is something else.

Quem mais tem interesse

  • Customers and the public, whose data the organisation holds.
  • Every team whose work the policy constrains.
  • Insurers, regulators and, after an incident, the courts.

O que exige

  • Technical credibility sufficient to be told the truth by the people who have it.
  • Fluency in risk, budget and the language a board makes decisions in.
  • The composure to be accountable for outcomes produced by systems and people beyond direct control.
  • The judgement to say what the organisation is choosing to accept, and to have it recorded as a choice.

Do que o trabalho depende

The role is accountable for an outcome it produces through other people's budgets and other people's priorities. Authority over policy is real and authority over the engineering that implements it usually belongs to somebody else, so the work is persuasion carried out with a mandate. Leaders who last make the risk legible to the people who hold the budget, and record what the organisation decided to accept — because the record is what turns a later incident from a failure of the programme into a consequence of a decision somebody made knowingly.

As fontes publicadas

Para onde leva

O trabalho em si

A Prática cobre como este trabalho é feito — triagem, escalação, evidência, passagem de bastão — em todo o corpus.

Ler A Prática