The security advisory function’s effectiveness depends not only on the quality of the security knowledge it brings to the business engagement but on the principles that govern how that knowledge is applied, communicated, and aligned with the organisation’s operational and strategic context. The principles that follow provide the architectural and philosophical foundation for the security consulting function, ensuring that every advisory engagement produces recommendations that are strategically grounded, commercially relevant, technically sound, and practically implementable within the business environment the advisory must serve.
These principles represent more than a catalogue of best practices. Together they constitute the advisory philosophy that distinguishes the security consulting function that genuinely enables business performance from the security function that the business experiences as the technically competent but commercially tone-deaf obstacle whose advice must be accommodated rather than embraced. The ISO who governs every advisory engagement through these principles will build the trusted adviser relationship that the security consulting function’s strategic value requires and that the business’s confidence in the security function’s commercial awareness enables.
Fact-Based Advisory #
The foundation of credible security advisory is the empirical evidence and observable data that grounds recommendations in the demonstrable rather than the speculative. The security adviser who relies on anecdote, convention, and assumption rather than the quantifiable evidence that scrutiny can assess will consistently produce recommendations whose defensibility the business’s commercial challenge requires but the advisory’s evidential basis cannot provide.
The fact-based approach requires the ISO to enter every advisory engagement with the intellectual openness that genuine evidence-based analysis demands, including the willingness to reassess long-held security convictions when the data that the specific organisational context provides challenges the conventional wisdom that the broader professional community has established. The security practice that is standard across the industry may not be the appropriate recommendation for the specific organisation whose asset profile, threat landscape, and operational context differs materially from the profile that the standard practice was designed to address.
Keep reading with a free Eristotle account.
Every document across our Bodies of Knowledge is free to read once you are signed in. No payment, no tier.
