3 ms·
CIO to me is just a job that the CEO can cut loose if some disaster happens to save his ass. Nobody needs a CIO around to ponder about IT security. It's somet
by codeonfire 13y ago
CIO to me is just a job that the CEO can cut loose if some disaster happens to save his ass. Nobody needs a CIO around to ponder about IT security. It's something that has to be owned by individual admins and developers. The CIO can dictate strategy or policy or whatever, but its going to be individual mistakes like playing loose with credentials or messing up configuration that lead to data breaches.
- rdl 13y agoCIO is a lot more than security. In some companies, CIO is on par with CFO in importance. CISO sort of exists to get thrown under the bus, but in a regulated industry, has a huge compliance role. The whole point of policy is to resource the whole thing adequately so individual mistakes get prevented, or caught and corrected, before they turn into a Target-scale problem. But that usually requires doing more than just bare compliance minimums, and is only possible with board level support for that kind of thing. Probably exists at Target now. Probably didn't before.