From the strategic vision that aligns security with business goals to the operational practices that keep risk in check, this framework delivers a structured path for building and managing an effective corporate information security organization. It addresses the full range of capabilities required for business-driven security outcomes, including governance, operational excellence, and tactical readiness. It emphasizes continuous alignment with evolving business priorities, optimization of processes and controls, and the cultivation of security leadership that enables the organization to operate with confidence in a dynamic risk environment.
Eristotle’s Competency Model for the Information Security Office Domain is specifically tailored for building and operating a robust and relevant security organization and aligns skill sets to key functional areas.
Security Leadership
Competency
Description
Proficiency Level
Strategic Visioning
Defines and articulates a long-term security vision aligned with business goals.
Advanced → Expert
Executive Influence
Secures buy-in from C-level leadership and Board of Directors.
Advanced → Expert
Risk-Based Prioritization
Aligns security initiatives with enterprise risk appetite and priorities.
Advanced → Expert
Policy Formulation
Develops enforceable security mandates and charters.
Advanced
Budget & Resource Management
Secures and allocates resources to build and sustain a security program.
Applied → Adaptive
Regulatory Awareness
Understands applicable laws, standards, and regulatory obligations.
Applied → Adaptive
Security Governance, Risk and Compliance
Competency
Description
Proficiency Level
Governance Framework Design
Implements frameworks (e.g., ISO 27001, NIST CSF, COBIT) to guide security practices.
Expert
Policy and Standards Management
Develops, publishes, and enforces information security policies and standards.
Applied → Adaptive
Security Risk Management
Identifies, assesses, and mitigates risks across the enterprise.
Advanced
Compliance Monitoring
Ensures alignment with internal policies and external regulatory requirements.
Applied → Adaptive
Metrics and KPIs Development
Defines indicators to measure control effectiveness and program maturity.
Applied → Adaptive
Third-Party Risk Oversight
Manages risks associated with vendors and supply chains.
Applied → Adaptive
Security Culture
Competency
Description
Proficiency Level
Security Awareness Training
Develops and delivers targeted training programs for staff.
Applied → Adaptive
Behavioral Change Enablement
Drives cultural change toward proactive security behaviors.
Applied → Adaptive
Leadership Engagement
Influences line managers and leadership to reinforce security values.
Advanced
Gamification & Engagement Techniques
Uses innovative methods (e.g., phishing simulations, capture-the-flag) to enhance learning.
Applied → Adaptive
Metrics on Culture Maturity
Measures progress toward a mature security-aware culture.
Intermediate
Security Consulting
Competency
Description
Proficiency Level
Business Risk Translation
Converts technical risk into language understood by business stakeholders.
Advanced
Architecture & Design Review
Advises on secure design of systems, applications, and networks.
Applied → Adaptive
Threat Modeling
Identifies potential attack vectors during the system development lifecycle.
Applied → Adaptive
Control Design and Implementation
Recommends and helps implement security controls across business units.
Applied → Adaptive
Stakeholder Engagement
Builds strong relationships with IT, Legal, HR, and other departments.
Applied → Adaptive
Cloud and DevSecOps Advisory
Guides secure cloud architecture and DevOps practices.
Applied → Adaptive
Security Operations
Competency
Description
Proficiency Level
Security Monitoring & Detection
Operates and tunes SIEM, IDS/IPS, and other detection tools.
Expert
Incident Response
Investigates and contains security incidents with minimal business disruption.
Expert
Threat Intelligence
Collects and applies threat intelligence to anticipate and defend against attacks.
Applied → Adaptive
Vulnerability Management
Scans, assesses, and remediates security weaknesses.
Applied → Adaptive
Access and Identity Management (IAM)
Ensures secure user provisioning, authentication, and authorization.
Applied → Adaptive
Endpoint and Network Security
Protects infrastructure through layered defense strategies.
Applied → Adaptive
Security Reporting
Competency
Description
Proficiency Level
Dashboard and Metrics Reporting
Develops security dashboards for visibility into risk posture.
Applied → Adaptive
Board-Level Communication
Prepares risk and incident summaries for executives and the Board.
Advanced → Expert
Control Effectiveness Reporting
Evaluates the health and performance of implemented controls.
Applied → Adaptive
Regulatory & Audit Reporting
Responds to audits and regulatory reporting requirements.
Applied → Adaptive
Root Cause & Post-Incident Analysis
Produces meaningful postmortems to drive continual improvement.
Applied → Adaptive
Report
There was a problem reporting this post.
Block Member?
Please confirm you want to block this member.
You will no longer be able to:
See blocked member's posts
Mention this member in posts
Invite this member to groups
Message this member
Add this member as a connection
Please note:
This action will also remove this member from your connections and send a report to the site admin.
Please allow a few minutes for this process to complete.