International principles for boards of directors and cyber security
Larry Clinton
Additional contact information
Larry Clinton: Internet Security Alliance, USA
Cyber Security: A Peer-Reviewed Journal, 2021, vol. 4, issue 3, 243-250
Abstract:
As threats emanating from poor cyber security have grown, calls for boards of directors to become more involved as have also grown. The exact role of the board, as opposed to management, in this new field has been murky, however, and effective steps at the board level have not previously been clearly defined. The Internet Security Alliance (ISA), in conjunction with organisations representing corporate board members and governments on four continents, conducted grounded research involving hundreds of directors, senior management government and academic responders. The ISA research generated a series of open source cyber risk handbooks. The handbooks articulated a common set of five core principles and practical steps to implement them. This paper discusses these principles, which include items boards need to be aware of in their own operations, as well as delineating the board’s role in setting expectations for management. Although the core principles were supported by all participating organisations, adaptations were required to reflect differences in culture, board structure and law. The principles depart in significant ways from many commonly held assumptions about addressing cyber risk. For example, the very first principle is that boards need to conceptualise cyber security not as an ‘IT issue’ but as a broader risk management issue. Other principles urge boards to understand their unique legal obligations and access appropriate expertise. Boards are also urged to consider restructuring their cyber security management teams away from their current IT focus and urge management to adopt new cyber risk assessment techniques conceptualising cyber risk in empirical and economic terms. Although not part of the ISA research, the paper reports on an independent assessment PwC conducted on use of the handbooks. PwC’s ‘Global Information Security Survey’ reported use of the handbooks generated higher budgets, better risk management, closer alignment between cyber security and business goals and helped generate a culture of security
Keywords: cyber security; effective; principles; boards; international (search for similar items in EconPapers)
JEL-codes: M15 (search for similar items in EconPapers)
Date: 2021
References: Add references at CitEc
Citations:
Downloads: (external link)
https://hstalks.com/article/6090/download/ (application/pdf)
https://hstalks.com/article/6090/ (text/html)
Requires a paid subscription for full access.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:aza:csj000:y:2021:v:4:i:3:p:243-250
Access Statistics for this article
More articles in Cyber Security: A Peer-Reviewed Journal from Henry Stewart Publications
Bibliographic data for series maintained by Henry Stewart Talks ().