I recently finished the book "Traction" by Gino Wickman. Next to Scaling-Up by Verne Harnish, I think it is one of the most actionable business books I've ever read. Our team has informally adopted both books as part of the risk3sixty cannon. While the book is largely about building a great running business - I think a lot of the same lessons can be applied to building a well-oiled information security program. If your security organization hasn't formally adopted these action items - then you will probably get a lot of value out of reading "Traction".
THE QUARTERLY STRATEGY ALIGNMENT MEETING
THE ANNUAL OFF-SITE MEETING
Does Your CISO Do This?
1 | Have you clearly defined roles and responsibilities within the security organization? 2 | Does each role owner have a specific set of objectives to accomplish this week, this quarter, this year? 3 | Do you have regular meetings to measure results and track progress against mission objectives? 4 | Have you established measurable KPIs (a scorecard) with defined owners within the security organization? 5 | Have you defined the security organization's mission, core values, and vision? 6 | Does all of this align with the business's objectives?Battle Rhythm - Something You Can Start Today
If you haven't done so already, working through the list above (in order) is worth the time and effort. For the average-sized security team, it might take 6 - 12 months to work out the kinks, but it will change the way your security team operates for the better. But one thing you can do today is establish an effective set of standing meetings to "operationalize" your security team.Here is your new meeting cadence:
THE WEEKLY TACTICAL MEETING| MEETING PURPOSE | Review KPIs, Align on mission for the week, Discuss any immediate barrier |
| WHO SHOULD ATTEND | The whole team (If more than 10, start sub-weekly meetings) |
| DURATION | 60-90 minutes (ours is 60 minutes) |
| MEETING AGENDA |
|
| PURPOSE | Review scorecard trend, Assess progress toward mission, Discuss any major changes |
| WHO SHOULD ATTEND | Management Team |
| DURATION | 2 – 8 hours (ours is 2 hours) |
| MEETING AGENDA |
|
| MEETING PURPOSE | Set the mission/vision for the year, define goals, clarify roles, adjusts KPIs, how this all fits with the businesses objective |
| WHO SHOULD ATTEND | The Management Team |
| DURATION | (ours is usually 2.5 days of work, half day of fun) |
| WHERE | Off-site, if possible |
| MEETING AGENDA |
|
Let's Get Started
If you or your team need help taking your security program to the next level, please contact us.
Christian Hyatt
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)