Os Papéis · Quem defende
Security leader
Escrito a partir de fontes publicadas
The top of the management arm, in security. The framework describes the work as establishing vision and direction for an organisation's cybersecurity operations and resources, with the authority to make decisions that reach the whole organisation, approve policy and engage stakeholders. The ladder below it runs manager, then director, then this — and each rung trades proximity to the work for reach across it.
De quem recebe
- The operations and response teams
- What is happening, at the fidelity the tooling allows.
- The business
- Where it is going, which decides what has to be protected next.
- Regulators, auditors and insurers
- Obligations that arrive with dates attached.
A quem serve
- The board and executive
- Risk expressed in terms they can decide with.
- The security teams
- Direction, resources, and cover when a decision proves unpopular.
- The rest of the organisation
- Policy that can be followed by people whose job is something else.
Do que o trabalho depende
The role is accountable for an outcome it produces through other people's budgets and other people's priorities. Authority over policy is real and authority over the engineering that implements it usually belongs to somebody else, so the work is persuasion carried out with a mandate. Leaders who last make the risk legible to the people who hold the budget, and record what the organisation decided to accept — because the record is what turns a later incident from a failure of the programme into a consequence of a decision somebody made knowingly.