CISO Toolkit: The Metric of No.
Amazon Web Services (AWS)
Official Global LinkedIn page for Amazon Web Services (AWS).
Saying “No” and being the “Department of No” are two different things. CISOs can use “No” to justify increased security and resilience while maintaining the pace of innovation that modern businesses demand.?
By Clarke Rodgers , Director of Enterprise Strategy at Amazon Web Services (AWS)
Many CISOs that I meet with globally have a common challenge they’re trying to overcome: to be viewed as business leaders
While it may seem counterintuitive, one of the best ways for the CISO to support their initiatives, and to be able to effectively communicate risk, is to track how many times they MUST say “No.” An organization with a strong security culture
Businesses are rapidly pursuing use cases for and implementing AI as quickly as possible, and security teams are balancing the need to support business innovationwhile mitigating risk for the organization.
History shows us that if CISOs are not supportive of business objectives, they lose visibility of company activities due to shadow IT and other end-runs around the security apparatus, further exposing the organization to unnecessary risk. At the dawn of cloud experimentation and migration more than a decade ago, some CISOs actively blocked cloud, were circumvented, and ended up having to bolt on security after the fact. Others took a more objective stance, learned about the security benefits of the cloud
Today, we see a similar conundrum: generative artificial intelligence (AI).?Businesses are rapidly pursuing use cases for and implementing AI as quickly as possible, and security teams are balancing the need to support business innovation while mitigating risk for the organization. The lessons CISOs learned from cloud adoption are finding their way into AI adaptation, and that is a great thing. However, for those CISOs who are not able to match the speed of their business, and have not yet earned the trust of their business peers, how can they shift from being viewed as blocker of innovation and instead be seen as a champion of it?
An example: Product delivery velocity.
领英推荐
Line of Business (LOB) owners: “We need to increase the velocity of our code releases to achieve better time to market, and increase revenues to meet the target set by the CEO. Security keeps blocking us right when we’re about to launch because they find security issues in our code and force us to do expensive rework that puts us further behind. We need to remove this burden, launch the release on schedule, and if there are any security issues, we can just put them in later via our backlog.”
CISO: “No. The risk is too high to the organization, we must be able to release code securely
How that “No” turns into an asset for getting to “Yes”:?
The CISO organization tracks how often this comes up across the various LOBs and what the “No” actually costs in terms of potential lost revenue. Using that data, they can then make the business case to obtain funding and buy-in for: 1/ incubating a security culture program where everyone has a security responsibility, 2/ justifying the cost of a tooling team that builds and maintains CI/CD pipelines with the security checks built in, not bolted on—so developers get security feedback at every stage of the SDLC and focus on features), 3/ building a training program and embeds a “Security Ambassador” in every product team, and 4/ making security objectives clear (we must do X, Y, and Z) yet flexible (Let's explore any options we can).
These strategies result in LOB developers having full control over their release velocity, ownership, and security of their product. Security is built in early with every product, with fewer (perhaps zero) expensive “night of production implementation” security blocks. LOB delivers code securely at the velocity that aligns with business objectives.?
Saying “No” and being “the Department of No” are two very different things. But CISOs have an opportunity to use “No,” in terms of business risk and opportunities, to justify increased security and resilience while maintaining the pace of innovation that modern businesses demand.
CEO at EZOps Cloud | Leading the future of DevOps with secure and efficient solutions allied with AI-powered innovation
1 年Excellent!
Student at Gayatri Institute of Science and Technology (GIST), Berhampur
1 年Very useful
Great read!
Applications Integration Specialist | Infrastructure | Market Data | Fixed Income | OAM&P
1 年Well said