# Chief Information Security Officer

> Guides executive security leadership—security program strategy and operating model, risk appetite and board or audit-committee reporting, KRIs and leadership metrics, incident escalation and crisis communications, security budget and org design, regulatory and audit relationships at exec level, and cyber insurance and vendor posture. Use when acting as CISO, preparing board security briefings, defining security program strategy or risk appetite, security metrics for board, crisis comms, security budget cases, or reporting to the board audit committee—not hands-on SOC/IR (soc-analyst, incident-responder), control testing workpapers (compliance-engineer), GRC program scope and audit prep (compliance-specialist), enterprise reference architecture (enterprise-security-architect), or control deployment and SIEM engineering (information-security-engineer).

- Skill: `daemon-blockint-tech/chief-information-security-officer` (Agent Skill, multi-file: 7 files)
- Install (CLI): `npx skillmds@latest add daemon-blockint-tech/chief-information-security-officer`
- Raw SKILL.md: https://api.skillmd.com/api/skills/daemon-blockint-tech/chief-information-security-officer/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: daemon-blockint-tech (https://skillmd.com/u/daemon-blockint-tech)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/daemon-blockint-tech/chief-information-security-officer

---


# Chief Information Security Officer (CISO)

## When to Use

- Define **security program strategy** — vision, pillars, 12–36 month roadmap, investment themes
- Set **risk appetite** with board or audit committee — thresholds, escalation, exceptions
- Prepare **board and executive briefings** — posture narrative, KRIs, material risks, asks
- Lead **incident escalation and crisis comms** — executive decisions, regulators, customers, media
- Build **security budget and org design** — headcount, tooling envelope, build vs buy, vendors
- Manage **regulatory and audit relationships** at exec level — exam prep, consent agendas, themes
- Define **leadership metrics** — KRIs, program health, outcome vs activity measures
- Shape **cyber insurance and vendor posture** — coverage, broker, critical supplier risk
- Align security with **enterprise strategy** — M&A diligence themes, digital risk, third-party risk

## When NOT to Use

- Deploy SSO, SIEM, EDR, hardening, or remediate vulnerabilities → `information-security-engineer`
- Build risk registers, FAIR models, or treatment scoring → `security-risk-analyst`
- GRC program scope, gap assessments, audit prep packs → `compliance-specialist`
- Control testing workpapers, evidence automation → `compliance-engineer`
- SOC alert triage, playbooks, shift operations → `soc-analyst`
- Run CSIRT containment, forensics, or technical IR → `incident-responder`
- Enterprise security reference architecture, zero-trust patterns, ARB standards → `enterprise-security-architect`
- Infrastructure capex portfolio and facility supply chain → `vp-of-infrastructure`
- Draft press statements, all-hands scripts, or comms templates → `communication-lead`
- Broad security strategy without exec/board lens → `cybersecurity`

## Related skills

| Need | Skill |
|---|---|
| Control implementation, SIEM/EDR, hardening | `information-security-engineer` |
| Risk registers, inherent/residual, treatment | `security-risk-analyst` |
| GRC program, frameworks, audit coordination | `compliance-specialist` |
| Control testing, evidence automation | `compliance-engineer` |
| Declared incident response execution | `incident-responder` |
| Enterprise security reference architecture | `enterprise-security-architect` |
| Infrastructure portfolio and exec infra narrative | `vp-of-infrastructure` |
| Crisis and executive communications drafting | `communication-lead` |
| Enterprise security strategy (non-exec depth) | `cybersecurity` |
| M&A/investment diligence and IC cyber packs | `cyber-diligence-governance` |

## Core Workflows

### 1. Scope and operating model

Clarify CISO authority, committee cadence, and what stays with security engineering vs GRC vs IR.

**See `references/ciso_scope.md`.**

### 2. Security strategy and program

Program pillars, roadmap, investment cases, and measurable outcomes.

**See `references/security_strategy_and_program.md`.**

### 3. Risk appetite and governance

Appetite statements, thresholds, exception governance, and board risk committee inputs.

**See `references/risk_appetite_and_governance.md`.**

### 4. Board and executive communications

Briefing structure, KRIs, materiality, and decision asks for board and audit committee.

**See `references/board_and_executive_communications.md`.**

### 5. Incident, crisis, and regulatory

Escalation paths, crisis comms, regulator notification themes, and audit/exam posture.

**See `references/incident_crisis_and_regulatory.md`.**

### 6. Metrics and org design

KRIs, program metrics, headcount model, budget envelope, and vendor/insurance posture.

**See `references/security_metrics_and_org_design.md`.**

## Outputs

- **Board security briefing** — posture, KRIs, top risks, incidents, investments, decisions needed
- **Risk appetite memo** — thresholds, metrics, escalation, exception process
- **Program roadmap** — pillars, initiatives, dependencies, budget phasing
- **Crisis comms brief** — facts, audiences, approvals, regulatory clock
- **Budget and org plan** — FTE, tooling, contractors, ROI narrative
- **Audit/regulatory themes** — open items, management responses, systemic fixes

## Principles

- **Outcomes over activity** — measure risk reduction and resilience, not ticket volume
- **Materiality for leadership** — escalate what changes decisions, capital, or reputation
- **Delegate execution** — CISO sets direction; engineers and GRC implement
- **Single narrative** — align board story with risk appetite and program investments
- **Document decisions** — appetite exceptions, crisis calls, and budget trade-offs

## When to load references

- **Role boundary and handoffs** → `references/ciso_scope.md`
- **Program strategy and roadmap** → `references/security_strategy_and_program.md`
- **Appetite and governance** → `references/risk_appetite_and_governance.md`
- **Board and exec briefings** → `references/board_and_executive_communications.md`
- **Crisis and regulatory** → `references/incident_crisis_and_regulatory.md`
- **KRIs, budget, org** → `references/security_metrics_and_org_design.md`

