WINNING AS A CISO is authored by Rich Baich, who is the former Chief Information Security Officer for ChoicePoint and the winner of the ISE in Georgia Award. This book provides an insider's view of how a world class security organization should be built and managed. Focused on leadership, driving change and tips on how to run your security program like a business, this book is an extraordinary read. WINNING AS A CISO is a sourcebook that every security executive should own.
The roles of the chief information officer (CIO), the chief security officer (CSO), and the chief information security officer (CISO) in the modern enterprise have been constantly changing since we invented the need for such roles in the 1980s and 1990s. By the mid-2000s, the industry had settled on tucking the security function for an organization under the IT function of an organization. In other words, the CISO works for the CIO. But Baich is an innovative thinker. He has looked at how the CISO role has evolved over the years and makes a pretty good case for where it needs to go next. By asking questions about the appropriate supervisor for a CISO, a CISO’s needed skill set, and ways to approach the CISO job function, Baich breaks new ground on how the industry should views these topics. Our industry will be slow to adopt these new ideas, but with the rash of highly publicized and impactful data breaches to the retail sector in 2014, perhaps the industry is ready to start making a change. Reviewing Baich’s book is a good place to start. It is cyber-security-canon worthy, and you should have read it by now. See the full review at the Cybersecurity Canon Website.