The Cyber Security Team
As a first step in the development and implementation of a cyber security program, management should establish a cyber security team that is responsible for ensuring data security, enforcing data policies and procedures, and assisting with, responding to and recovering from a suspected or actual data breach or interruption of network service and implementing corrective actions. Considerations for key team member responsibilities include:
Chief Information Security Officer (CISO) or equivalent
The CISO is the cyber risk management team leader and reports directly to senior management. A highly effective CISO is knowledgeable about business functions and regulatory requirements and responsible for developing budgets to develop, administer, and maintain the cyber security program. The CISO with authority across all departments or functions of your company and all third-party service providers to monitor and enforce the cyber security program policies and controls may be in the best position to confirm that the policies and controls are consistently deployed, followed and enforced.
The CISO leads the risk assessment process to help identify the likelihood of cyber security threats and their potential impact to the business. Assessment of threat can include both deliberate and accidental threats, insider attacks, past incidents and detailed awareness of new types of attack. The threats can be prioritized and the adequacy of the existing technological and administrative controls to minimize these threats can be assessed. A process can be established to prioritize and implement cyber security technological and administrative actions to address identified gaps. The cyber security plan should be included within the company’s business continuity plan.
Cyber security team responsibilities
The CISO should select team members who represent various areas of your company to have responsibility for the security of data, applications, systems and networks. Team members may be assigned partial roles or given multiple responsibilities. Some positions, skill sets and job responsibilities to consider include, but are not limited to:
Information network administrators
Personnel with the IT technical expertise needed to protect and maintain your network and responsibility to collaborate with your business managers to determine and prescribe the authorized software and equipment that will be allowed on the network.
Legal counsel
Cyber security and privacy rights regulations have been enacted by numerous countries, the U.S. federal government and individual states. It is essential that your business be knowledgeable about your contractual, legal and regulatory requirements. Legal counsel can provide guidance to help ensure that your company and your third-party providers are in compliance with these requirements.
Human resources
Human Resources personnel can help companies develop and implement policies and training that establish a common understanding of the expectations your company has of your employees regarding work, the work environment and employee behavior.
Business managers
Business managers are responsible for knowing and classifying, by sensitivity level, the types of information needed within their departments, establishing who is authorized to access the data and ensuring their department(s) are in compliance with company cyber security policies.
Webmaster
Businesses that maintain websites to advertise their products and services or conduct business transactions can have a dedicated webmaster or contract with a service provider to manage their website. Because information on these publicly accessible web servers can be inherently more vulnerable, the webmaster or service provider can be an important member of the cyber security team.
Facilities manager
To prevent physical damage, unauthorized access or theft, a person responsible for maintaining the building physical protection and security controls should be assigned.
Third-party service providers
Third-party service providers, such as ISP providers, hardware, software and firmware vendors and other third-party providers who perform services on behalf of your company and may have access to sensitive data, should be considered for inclusion on the team.
Incident response team
Every business should plan for the unexpected. A highly effective incident response plan can help to define which types of incidents you can handle yourself and which types you cannot. Consider determining if your organization has the skills, resources and time to investigate, quantify and recover from an incident. Your incident response team can include members from your cyber security team and can include contractual agreements as needed with third parties that specialize in digital forensics and recovery.
Segregation of duties
Care can be taken so that no single person can perpetrate fraud in areas of single responsibility without being detected. Segregation of duties is a method for reducing risk of accidental or deliberate system misuse. Small companies may find this method of control difficult to achieve, but the principle can be applied where possible and practical.
Staying current
To stay current, members of the team can subscribe to or participate with organizations that are active with cyber security technology and regulatory changes.