CMU5XX-INFOSEC
Information Security for Industry
Session 9: Enterprise Roles & Security Governance
Learning Objectives
- Analyze the evolving role of the Chief Information Security Officer (CISO).
- Evaluate organizational reporting structures and the conflict of interest between IT and Security.
- Understand the responsibilities of the Board of Directors regarding cyber risk.
- Design effective Security Steering Committees.
- Utilize RACI matrices to clarify operational security accountability.
Seminar Structure (3 Hours)
Part 1: Executive Roles (1.5 hrs)
- The CISO, the CIO, and the Board
- Reporting Structures and Conflicts of Interest
- Task 1: The Board Presentation
Part 2: Operational Governance (1.5 hrs)
- Security Steering Committees
- Responsibility Assignment Matrices (RACI)
- Task 2: Designing a Security RACI
Part 1: Executive Roles
Duration: 1.5 Hours
The Chief Information Security Officer (CISO)
The CISO is no longer a purely technical role; it is a business risk role.
- Historically: A senior network engineer who configured firewalls.
- Modern Era: A business executive who aligns security strategy with organizational goals, manages regulatory compliance, and speaks the language of risk to the board.
- The modern CISO must balance the need for security with the business's need to generate revenue rapidly.
The Reporting Conflict
Who should the CISO report to?
- Reporting to the CIO (Bad Practice): The Chief Information Officer's primary goal is uptime, speed, and cutting IT costs. Security is expensive and introduces friction. If the CISO reports to the CIO, security concerns are often overruled to meet IT deadlines.
- Reporting to the CEO or Risk Officer (Best Practice): Elevates security to a peer-level with IT, allowing the CISO to challenge the CIO on insecure architectures without fear of being fired by them.
The Board of Directors
Fiduciary Duty and Cyber Liability.
- The Board is legally responsible for overseeing enterprise risk. Following massive breaches (e.g., Equifax, Yahoo), courts have held boards liable for gross negligence in cybersecurity oversight.
- The Board does not manage security; they demand assurance that management is handling it effectively.
- They ask three questions: Are we secure? Are we compliant? Are we spending the right amount?
Introduction to Task 1
Presenting a major security incident to a non-technical board requires filtering out operational details and focusing entirely on business impact, containment, and liability.
We will draft a post-incident board briefing.
Task 1: The Board Presentation
Timing: 45 minutes
You are the CISO. Last night, an attacker successfully exfiltrated a database containing 50,000 customer credit card records by exploiting a SQL injection vulnerability in a legacy web portal.
- Draft a concise opening statement (max 3 sentences) informing the board of the breach. (Do not use the terms "SQL", "Injection", or "Exfiltration").
- Outline the three immediate business impacts the board needs to prepare for (e.g., regulatory fines, public relations).
- Propose a high-level strategic request to the board to ensure this specific class of vulnerability is eliminated across the enterprise.
15 Minute Break
Please return promptly for Part 2.
Part 2: Operational Governance
Duration: 1.5 Hours
Security Steering Committees
Security cannot exist in a vacuum. It must have organizational buy-in.
- A cross-functional group (IT, HR, Legal, PR, Business Unit Leaders) that meets quarterly to review security posture.
- Purpose: To ensure security initiatives align with upcoming business projects. If the business is launching a new mobile app, the committee ensures security is involved from day one.
- Breaks down silos and distributes ownership of security risk across all department heads.
The RACI Matrix
When everyone is responsible, nobody is responsible. RACI defines exact roles for a process.
- Responsible: The person doing the actual work (e.g., the Engineer patching the server).
- Accountable: The person whose head rolls if it fails. Only ONE person can be accountable (e.g., the IT Director).
- Consulted: Subject matter experts asked for input before the work (e.g., the Security Team reviewing the patch).
- Informed: People told after the work is done (e.g., the Helpdesk notified that servers were rebooted).
Applying RACI in Security
Security teams often fail because they try to be 'Responsible' for everything.
- The Security team does not own the servers; IT owns the servers. Therefore, Security cannot be Responsible for patching them.
- Security sets the policy (Standard), IT executes the work (Responsible), and Security audits the result.
- Clear RACI matrices prevent the classic "finger-pointing" match between IT and Security during an incident post-mortem.
Introduction to Task 2
Drafting a RACI matrix forces organizations to confront ambiguous ownership and clarify operational workflows before an incident occurs.
We will design a RACI matrix for managing employee terminations (offboarding).
Task 2: Designing a Security RACI
Timing: 50 minutes
Process: Revoking corporate network access when an employee is terminated.
Roles available: HR Manager, IT Administrator, CISO, Direct Manager.
- Assign the R, A, C, and I roles to the four available positions for this specific process. (Remember: Only one person can be 'A').
- Justify your choice for who is Accountable. Why is this role ultimately answerable if access is not revoked and the ex-employee steals data?
- Explain why the CISO should generally be 'Consulted' or 'Informed' on operational IT tasks, rather than 'Responsible'.
Summary & Next Steps
- The CISO must bridge the gap between technical reality and board-level business risk.
- Governance structures (like Steering Committees and RACI matrices) replace ad-hoc heroics with repeatable, accountable processes.
Next Week: Developing Security Plans (Actionable Security)