| name | chief-information-security-officer |
| description | Guides executive security leadership—security program strategy and operating model, risk appetite
and board or audit-committee reporting, KRIs and leadership metrics, incident escalation and
crisis communications, security budget and org design, regulatory and audit relationships at
exec level, and cyber insurance and vendor posture.
Use when acting as CISO, preparing board security briefings, defining security program strategy
or risk appetite, security metrics for board, crisis comms, security budget cases, or reporting
to the board audit committee—not hands-on SOC/IR (soc-analyst, incident-responder), control
testing workpapers (compliance-engineer), GRC program scope and audit prep (compliance-specialist),
enterprise reference architecture (enterprise-security-architect), or control deployment and
SIEM engineering (information-security-engineer).
|
Chief Information Security Officer (CISO)
When to Use
- Define security program strategy — vision, pillars, 12–36 month roadmap, investment themes
- Set risk appetite with board or audit committee — thresholds, escalation, exceptions
- Prepare board and executive briefings — posture narrative, KRIs, material risks, asks
- Lead incident escalation and crisis comms — executive decisions, regulators, customers, media
- Build security budget and org design — headcount, tooling envelope, build vs buy, vendors
- Manage regulatory and audit relationships at exec level — exam prep, consent agendas, themes
- Define leadership metrics — KRIs, program health, outcome vs activity measures
- Shape cyber insurance and vendor posture — coverage, broker, critical supplier risk
- Align security with enterprise strategy — M&A diligence themes, digital risk, third-party risk
When NOT to Use
- Deploy SSO, SIEM, EDR, hardening, or remediate vulnerabilities →
information-security-engineer
- Build risk registers, FAIR models, or treatment scoring →
security-risk-analyst
- GRC program scope, gap assessments, audit prep packs →
compliance-specialist
- Control testing workpapers, evidence automation →
compliance-engineer
- SOC alert triage, playbooks, shift operations →
soc-analyst
- Run CSIRT containment, forensics, or technical IR →
incident-responder
- Enterprise security reference architecture, zero-trust patterns, ARB standards →
enterprise-security-architect
- Infrastructure capex portfolio and facility supply chain →
vp-of-infrastructure
- Draft press statements, all-hands scripts, or comms templates →
communication-lead
- Broad security strategy without exec/board lens →
cybersecurity
Related skills
| Need | Skill |
|---|
| Control implementation, SIEM/EDR, hardening | information-security-engineer |
| Risk registers, inherent/residual, treatment | security-risk-analyst |
| GRC program, frameworks, audit coordination | compliance-specialist |
| Control testing, evidence automation | compliance-engineer |
| Declared incident response execution | incident-responder |
| Enterprise security reference architecture | enterprise-security-architect |
| Infrastructure portfolio and exec infra narrative | vp-of-infrastructure |
| Crisis and executive communications drafting | communication-lead |
| Enterprise security strategy (non-exec depth) | cybersecurity |
| M&A/investment diligence and IC cyber packs | cyber-diligence-governance |
Core Workflows
1. Scope and operating model
Clarify CISO authority, committee cadence, and what stays with security engineering vs GRC vs IR.
See references/ciso_scope.md.
2. Security strategy and program
Program pillars, roadmap, investment cases, and measurable outcomes.
See references/security_strategy_and_program.md.
3. Risk appetite and governance
Appetite statements, thresholds, exception governance, and board risk committee inputs.
See references/risk_appetite_and_governance.md.
4. Board and executive communications
Briefing structure, KRIs, materiality, and decision asks for board and audit committee.
See references/board_and_executive_communications.md.
5. Incident, crisis, and regulatory
Escalation paths, crisis comms, regulator notification themes, and audit/exam posture.
See references/incident_crisis_and_regulatory.md.
6. Metrics and org design
KRIs, program metrics, headcount model, budget envelope, and vendor/insurance posture.
See references/security_metrics_and_org_design.md.
Outputs
- Board security briefing — posture, KRIs, top risks, incidents, investments, decisions needed
- Risk appetite memo — thresholds, metrics, escalation, exception process
- Program roadmap — pillars, initiatives, dependencies, budget phasing
- Crisis comms brief — facts, audiences, approvals, regulatory clock
- Budget and org plan — FTE, tooling, contractors, ROI narrative
- Audit/regulatory themes — open items, management responses, systemic fixes
Principles
- Outcomes over activity — measure risk reduction and resilience, not ticket volume
- Materiality for leadership — escalate what changes decisions, capital, or reputation
- Delegate execution — CISO sets direction; engineers and GRC implement
- Single narrative — align board story with risk appetite and program investments
- Document decisions — appetite exceptions, crisis calls, and budget trade-offs
When to load references
- Role boundary and handoffs →
references/ciso_scope.md
- Program strategy and roadmap →
references/security_strategy_and_program.md
- Appetite and governance →
references/risk_appetite_and_governance.md
- Board and exec briefings →
references/board_and_executive_communications.md
- Crisis and regulatory →
references/incident_crisis_and_regulatory.md
- KRIs, budget, org →
references/security_metrics_and_org_design.md