enterprisesecuritymag

APRIL - 2023ENTERPRISE SECURITY| | 19CXO INSIGHTSEFFECTIVE STRATEGY TO ESTABLISH AND IMPLEMENT INFORMATION SECURITY IN AN ENTERPRISE ORGANIZATIONBy Sovattha Kao, Head of Information Security Department, Amret MFIBeing as a cyber security or information security leader in an enterprise organization, especially banking and financial industry, you are going to face various challenges in every single step of your journey, especially in the pandemic circumstance. You should have a very comprehensive strategy dealing with this sophisticated work. It requires a strong knowledge and experiences both technical skill which is functional skill and management that is the cross-functional skill. I would share these few tips, and I believe it would be work well for a new leader that was starting from a technical experience.Key DriversWhen you are on boarding the new enterprise organization, you have a very short time to learn and observe as much as possible about the company culture, environment, people, strategy, mission, vision, etc. The most important and it is a key successful for cyber security leader, you need to identify the key influencer or sometime known as key drivers for adding more value on your job. The key drivers are including Law, Regulatory, Standard Compliant, Parent Company (if you are a subsidiary), the Board of Director or the executive management in your company; these are the vital to support your security project proposal or implementation are going effectively and efficiency.Management Buy-InThe second important job that you need to accomplish with a very strong communication skill and business management principle for convincing the top management or the committee to buying-in your initiative idea, proposal or project. It is absolutely requiring you to have the Sovattha Kao
< Page 9 | Page 11 >