So, who should be on my IRC?
We get this question a lot, so here are some individuals and teams we suggest you include, and considerations for why you may or may not want to include them. These are in no particular order, and titles will vary somewhat depending on the size of your organization. The essential goal here is to establish an impactful and cross-functional team with the authority and insight to align your security program to your business strategy.Members to Consider:
- Chief Technology Officer: Often also the security program sponsor, the CTO serves as a bridge between the security program and the business objectives established by executive leadership. (Note: If you are not a SaaS/tech firm, you may want to include the VP of Services or Chief Operating Officer instead.)
- VP of Engineering: The person responsible for managing your SaaS platform fills a critical role by ensuring that change management processes and infrastructure efforts are aligned with the security objectives.
- CISO/VP of Security: Independent of their title/role, the person responsible for the effective operation of security initiatives should always be included in your IRC.
- General Counsel: Legal professionals often have the best understanding of the risks the organization faces and security commitments that the organization has made.
- Director of Compliance: This position is critical if you have a team dedicated to financial compliance initiatives such as SOC 1 or SOX, as there will be overlapping areas of risk management.
- HR/Chief People Officer: People are key to any organizational initiative, so having your HR team on board will help provide valuable feedback on your company's security implementation.
- Director of IT: This person is usually responsible for the operations of various security controls and making sure security objectives are technically feasible.
- Sales: Your sales team is often closest to the customer, the market's expectations for security, and the specific expectations clients have in this realm.
Phillip Lee
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)
