A CISO’s Guide to Security Outsourcing
Daniel Wallace, CISSP, PMP, Information Security Consultant at Grow Forward
While the responsibility for information security’s daily care and feeding can be outsourced, the accountability for compliance, information protection, and assurance will still reside within the organization usually in the CISO’s office.
Is the CISO-as-a-Consultant Model Obsolete?
Daniel Wallace, CISSP, PMP, Information Security Consultant at Grow Forward
Compounding the problem for the consultant CISO in the shorter term is that budgets are under downward pressure while the risk of fraud, insider theft and 3rd party exposure is going up. Longer term the financial crisis has forced firms to re-focus on systemic risk resulting in a revival of top-down Enterprise Risk Management efforts.
Making PCI Stand For Coordination & Impact
Daniel Wallace, Information Security Consultant
It will be no small task in terms of cost and effort for many of the impacted companies to make the transition from self-assessment to onsite 3rd party assessment. However, there are ways to lessen the burden and actually drive business-value from the engagement.


