Security Tenets

Spend long enough in this industry and you will meet two types of security professional.

The first knows their tools. They can talk you through a vulnerability assessment, configure a SIEM, and quote the relevant clause of ISO 27001 from memory. They are technically sharp, often impressive, and frequently ineffective at the level that matters most – the level where security decisions get funded, prioritised, and actually followed.

The second type does something different. They understand why security works the way it does. They can explain a risk to a CFO without losing the CFO. They know that a security programme is not a collection of controls — it is a reflection of what an organisation believes about risk, about accountability, about its own future. And because they understand that, they can lead one.

That distinction is what this module is about.

Before we go anywhere near the six domains of this programme, i.e. leadership, culture, governance, consulting, operations, and reporting, we need to establish the foundation they all stand on. Eleven tenets. Not rules. Not a checklist. A way of thinking about security that should shape every decision you make as an Information Security Officer.

Some of these will feel familiar. A few will challenge assumptions you have held since early in your career. That is intentional.

A CISO who cannot articulate why they do what they do is just an experienced practitioner with a senior job title.

This module is where we close that gap.

Not Enrolled
This course is currently closed

Course Includes

  • 12 Lessons
  • 1 Quiz