Site icon IT World Canada

How to talk to the board about IT security

The RSA Conference kicked off this week with a bevy of product announcements. Photo from RSA Conference.

Talking to a board of directors is one of the things CISOs or their equivalents have to get used to, especially these days when security is top of mind at the top of the organization.

It may not be easy to face a number of men and women who have little knowledge about what you do (and who assume the reason you’re there is to to ask for money). But as the RSA Conference was told this week, with some preparation

Chris Wysopal, co-founder and CTO of Veracode, told a session that you should think how you’d explain what you do when talking to your mother. Well, maybe that’s too simplistic (or maybe not). But here’s a few of his tips:

Here’s another sage piece of advice from Wysopal:  Ask board members what they want to get out of their infosec program. That will drawn them into a conversation, get them thinking about security and give you and the CEO an indication of the direction the board is going.

And if they’re caught off guard by the question? Well, then both sides have learned.

Exit mobile version