<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Solarwinds fallout, sue the C-Suite or the CISO? in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46987#M451</link>
    <description>&lt;P&gt;I was about to say a similar thing&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/783051913"&gt;@Steve-Wilme&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Collective failure can not be apportioned 100% to one individual - otherwise you're just creating scapegoats to insulate position of power that are the only ones who are empowered to change the outcome.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the correct answer is: The Board, The CEO &amp;amp; The CISO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Collective failure = collective fault.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Aug 2021 11:29:39 GMT</pubDate>
    <dc:creator>SWALTERS</dc:creator>
    <dc:date>2021-08-18T11:29:39Z</dc:date>
    <item>
      <title>Solarwinds fallout, sue the C-Suite or the CISO?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46984#M449</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An interesting article about whether suing the C-Suite is appropriate or the CISO.&amp;nbsp; What are your thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.secureworld.io/industry-news/ciso-lawsuit-solarwinds" target="_blank"&gt;https://www.secureworld.io/industry-news/ciso-lawsuit-solarwinds&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:57:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46984#M449</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T09:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Solarwinds fallout, sue the C-Suite or the CISO?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46986#M450</link>
      <description>&lt;P&gt;Surely it depends on the actual level of authority the CISO has in a particular organisation, rather than the job title.&amp;nbsp; It would be inappropriate for companies to move to renaming a junior position CISO just to allow the board to sidestep legal actions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 07:04:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46986#M450</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2021-08-18T07:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Solarwinds fallout, sue the C-Suite or the CISO?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46987#M451</link>
      <description>&lt;P&gt;I was about to say a similar thing&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/783051913"&gt;@Steve-Wilme&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Collective failure can not be apportioned 100% to one individual - otherwise you're just creating scapegoats to insulate position of power that are the only ones who are empowered to change the outcome.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the correct answer is: The Board, The CEO &amp;amp; The CISO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Collective failure = collective fault.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 11:29:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46987#M451</guid>
      <dc:creator>SWALTERS</dc:creator>
      <dc:date>2021-08-18T11:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Solarwinds fallout, sue the C-Suite or the CISO?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46990#M452</link>
      <description>&lt;P&gt;From the way I understand it, you can name anyone you want in the lawsuit. It could be a lower level security analyst if the Plaintiff wanted to. Typically what will happen is the Org's legal team will defend the defendants if there wasn't any negligence found on their part.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this article brings up another good question though. Is it okay to file a law suite using the federal SEC laws following a security incident or breach? My initial reaction is no with how common place they are.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 13:14:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46990#M452</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2021-08-18T13:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Solarwinds fallout, sue the C-Suite or the CISO?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46999#M453</link>
      <description>&lt;P&gt;This is why it is important if you are in a CISO or senior cyber role to :&lt;/P&gt;&lt;P&gt;1) Effectively articulate the risk a certain vulnerability causes, and,&lt;/P&gt;&lt;P&gt;2) Ensure that the appropriate members of senior management are aware of it, and,&lt;/P&gt;&lt;P&gt;3) Ensure you have provided adequate guidance on risk reduction, mitigation, or acceptance, and,&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) Ensure that the actions taken or not taken are documented and kept for permanent records.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just creating and filling out a risk register does not absolve you from responsibility. You need to be able to ensure that you did your due diligence in making senior management aware of the risks in the environment and that you properly documented the steps taken by the company.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 16:00:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/46999#M453</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2021-08-18T16:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Solarwinds fallout, sue the C-Suite or the CISO?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/47003#M454</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1602421967"&gt;@CISOScott&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; In that case rather like a Solution Design methodology, we should then be recording all architectural and business decisions, whether they were accepted by the C-Suite or not and whether they were simply brushed under the carpet.&amp;nbsp; We should also as a living document capture the Risks, Assumptions, Issues and Dependencies in a Viability Assessment.&amp;nbsp;&amp;nbsp; This will protect the integrity of the CISO, but also provide hard evidence, if a law suit occurs, or an employment issue arise - this is often a discipline that all Architects adopt, and I think we need to spread this to other professional disciplines as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 20:24:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/47003#M454</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2021-08-18T20:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Solarwinds fallout, sue the C-Suite or the CISO?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/47013#M458</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1602421967"&gt;@CISOScott&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is why you have someone in business meetings surrounding these topics take minutes (notes) and store those in the archive. Sometimes we'll have to show those minutes as proof to our 3rd party auditors that we discussed particular topics.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 12:43:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Solarwinds-fallout-sue-the-C-Suite-or-the-CISO/m-p/47013#M458</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2021-08-19T12:43:24Z</dc:date>
    </item>
  </channel>
</rss>

