<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: General Counsel Should Lead Security Management and Risk in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/General-Counsel-Should-Lead-Security-Management-and-Risk/m-p/35031#M2605</link>
    <description>&lt;P&gt;Definitely not under the CIO. Under legal? Hmmmmm... Maybe you would have some more pull with the threat of legal action. I could see it being OK being under legal, unless you got stuck in legal purgatory every time you proposed a change or it took 6 weeks to ratify a Rules of Engagement (ROE) (yes that happened to me) so maybe it isn't the best. I have seen Risk Manager being placed under legal so they could help quantify risks and legal exposure of risks, but not for the CISO or ISSO roles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I like the CISO being their own C level position.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Apr 2020 19:40:29 GMT</pubDate>
    <dc:creator>CISOScott</dc:creator>
    <dc:date>2020-04-22T19:40:29Z</dc:date>
    <item>
      <title>General Counsel Should Lead Security Management and Risk</title>
      <link>https://community.isc2.org/t5/Tech-Talk/General-Counsel-Should-Lead-Security-Management-and-Risk/m-p/35023#M2604</link>
      <description>&lt;P&gt;I have read many articles on the appropriate placement off Information Security over the years.&amp;nbsp; There are many thoughts on it, some saying the CFO, some saying the CIO, others stating the Board, this is a new approach and wonder what others think on this one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a synopsis:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.todaysgeneralcounsel.com/gc-should-lead-security-management-and-risk/" target="_blank"&gt;https://www.todaysgeneralcounsel.com/gc-should-lead-security-management-and-risk/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can link to the full article but a little difficult to read:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://issuu.com/todaysgc/docs/todaysgeneralcounsel_spring2020/24" target="_blank"&gt;https://issuu.com/todaysgc/docs/todaysgeneralcounsel_spring2020/24&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with an alignment but am not convinced Legal should lead...........&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 15:01:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/General-Counsel-Should-Lead-Security-Management-and-Risk/m-p/35023#M2604</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-04-22T15:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: General Counsel Should Lead Security Management and Risk</title>
      <link>https://community.isc2.org/t5/Tech-Talk/General-Counsel-Should-Lead-Security-Management-and-Risk/m-p/35031#M2605</link>
      <description>&lt;P&gt;Definitely not under the CIO. Under legal? Hmmmmm... Maybe you would have some more pull with the threat of legal action. I could see it being OK being under legal, unless you got stuck in legal purgatory every time you proposed a change or it took 6 weeks to ratify a Rules of Engagement (ROE) (yes that happened to me) so maybe it isn't the best. I have seen Risk Manager being placed under legal so they could help quantify risks and legal exposure of risks, but not for the CISO or ISSO roles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I like the CISO being their own C level position.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 19:40:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/General-Counsel-Should-Lead-Security-Management-and-Risk/m-p/35031#M2605</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2020-04-22T19:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: General Counsel Should Lead Security Management and Risk</title>
      <link>https://community.isc2.org/t5/Tech-Talk/General-Counsel-Should-Lead-Security-Management-and-Risk/m-p/35039#M2608</link>
      <description>&lt;P&gt;The CISO should be their own C level, they take risks, they understand them, and they are expected to be an excellent communicator, and capable of deciphering technical jargon to business speak, along with a calm mind, whilst everyone else pulls there own out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 03:56:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/General-Counsel-Should-Lead-Security-Management-and-Risk/m-p/35039#M2608</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-23T03:56:23Z</dc:date>
    </item>
  </channel>
</rss>

