Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is tasked with fostering a stronger security-aware culture within an organization where security is often viewed as an impediment to innovation and speed. The organization has a strong, fast-paced 'move fast and break things' culture. Which of the following approaches is MOST likely to successfully integrate security into this organizational culture?

  1. AImplementing a 'Security Champion' program where key individuals from different departments are trained to embed security into their teams' innovative processes.
  2. BBlocking access to unapproved software and cloud services to force adherence to security policies.
  3. CConducting quarterly executive briefings solely on the financial costs of recent security breaches in competitors.
  4. DImposing mandatory, lengthy security training sessions for all employees, emphasizing penalties for non-compliance.
Show answer & explanation

Correct answer: A. Implementing a 'Security Champion' program where key individuals from different departments are trained to embed security into their teams' innovative processes.

In a culture that values innovation and speed, a 'Security Champion' program is highly effective. It decentralizes security, integrates it into existing workflows through trusted peers, and positions security as an enabler rather than an impediment. This leverages the existing culture to promote security rather than fighting against it.

Why the other options are wrong

  • B. Blocking access can be seen as an impediment, leading to shadow IT and further resistance in a 'move fast' culture.
  • C. While financial costs are important, focusing solely on fear and competitor breaches may not resonate as effectively as integrating security into the innovation process itself.
  • D. Mandatory, lengthy training with penalties often creates resentment and reinforces the perception of security as a bottleneck.

Security Champion Program

An initiative that designates and trains individuals within various business units or teams to act as local security advocates, integrating security practices into their daily work and promoting security awareness.

  • Decentralizes security responsibility.
  • Leverages peer influence and existing team dynamics.
  • Helps embed security into workflows and culture organically.

Memory trick: Make security an inner voice, not an external nag.

More Information Security Governance questions