Not all executives are well versed in cyber security operations and costs. As a cyber security professional, it is my duty to explain to leadership how an Information System Security Plan (ISSP) is necessary for the security of the organization. Conversations around funding, ongoing budgets, BC, DR, and, ROI can give leadership the data they need to make effective decisions. Ensuring that leadership is apprised of compliance requirements and the costs of implementing those controls is part of a cyber security professional's job description.
Strong ethical leadership is necessary for managing these systems. This course taught me that the most successful cyber security professional is the one that can be absent for a period, and the program continues on without them. Planning for any event and ensuring that the organization can continue is paramount. Regular audits and reviews help strengthen the program and point out our weaknesses before they become vulnerable. Security is the responsibility of everyone; however, a good cyber security professional enables the organization to weather any adversity.