logo
Published on Security Incite: Analysis on Information Security (http://securityincite.com)

2007 DOI: Day 2 - CSO Next

By Mike Rothman
Created 2007-02-15 10:59

 

A new breed of CSO emerges in 2007, focused on running security as a business. High visibility, setting milestones, communicating progress, prioritizing fiercely, outsourcing strategically, managing vendors aggressively, and embracing advisors and coaches are the hallmarks of “CSO Next.” This Pragmatic CSO needs to look more like an MBA-type than a code jockey, which creates many challenges for the current generation of technically-oriented CSO.

 

The number of questions I get from readers and other industry contacts about the “type” of CSO that can be successful in today’s environment is shocking. But it indicates that the CSO role is in the middle of a significant transition - which is actually true. So in this Incite, I put together a little laundry list of the types of characteristics that I believe make up "CSO Next."

What the hell is CSO Next? Right, that doesn’t mean a hell of a lot, and many of these definitions are kind of motherhood and apple pie. But while you are asking, I figure I may as well eat some apple pie. Though I’m sure I’ll need to spend an extra 90 minutes or so on the treadmill to work it off.

Let’s also be clear that having all of these traits is not a requisite for success. But if you want to maximize your opportunity and have the most impact on your organization, you should probably start working on some of these skills, if they aren’t currently your forte.

 

You may be good at some of these things and need some improvement in others. And don’t sweat it if you don’t have an MBA. I don’t (much to the chagrin of my Dad). An MBA-type is as much philosophy and perspective as anything else. So think like a business-person and you will be perceived as a business person, and that’s what CSO Next is all about.

 


Source URL:
http://securityincite.com/blog/mike-rothman/2007-doi-day-2-cso-next