CISO 90 Days Plan 1716131454

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

CISO 90 Days Plan

Practical and Simple

PRABH NAIR
CISO BY DAY | MENTOR FOR LIFE
Week Tasks Objectives Key Deliverables

Week 1 Onboarding and Understand company culture - Initial meetings


Orientation schedule, List of key
Meet key stakeholders Review contact
existing documentation
Documentation
review summary

Week 2 Current State - Evaluate current security Security posture


Assessment posture report

Review past audits and incidents List of gaps and risks

Assess compliance with industry Compliance


standards assessment report

Week 3 Policy and Review existing security policies - Policy review


Procedure Review summary
Identify outdated or missing
policies List of recommended
policy changes
Suggest initial updates

Week 4 Team Assessment Meet with IT and security teams Team assessment
report
Evaluate team skills and roles
Training needs
Identify training needs analysis

Week 5 Risk Assessment Conduct a risk assessment Risk assessment


report
Identify critical assets and
vulnerabilities List of prioritized
risks
Prioritize risks

Week 6 Security Tools - Inventory current security tools - Tools inventory


and Technology
Review Evaluate effectiveness and gaps Gap analysis report

Recommend enhancements Recommended


enhancements list

Week 7 Develop Security - Draft a security roadmap Draft security


Roadmap roadmap
Align with business goals
Define short-term and long-term Alignment document
objectives with business goals

Week 8 Incident - Review existing incident - Incident response


Response Plan response plan plan review
Review
Conduct a tabletop exercise Tabletop exercise
report
Identify improvements
Improvement plan

Week 9 Compliance and - Ensure alignment with Compliance status


Regulatory regulatory requirements report
Alignment
- Prepare for upcoming audits Audit preparation
checklist
Address any compliance gaps

Week 10 Stakeholder - Develop a communication plan Communication plan


Communication for stakeholders
Plan Meeting schedule
Schedule regular updates
Executive summary
Prepare executive summaries templates

Week 11 Awareness and - Develop security awareness - Awareness program


Training Programs programs plan

-Plan training sessions for staff Training schedule

Launch initial training modules Initial training


materials

Week 12 Early Wins and Identify and execute quick wins Quick wins list
Quick Wins
Demonstrate immediate value Implementation
report
Communicate successes to
stakeholders Success
communication plan

Week 13 Feedback and Gather feedback from Feedback report


Adjustment stakeholders
Adjusted plans
Adjust plans based on feedback
Next quarter
Set priorities for the next quarter priorities

Week 14 Final Review and Prepare a comprehensive review Comprehensive


Presentation review document
Present findings and plans to
senior management Presentation slides

Discuss next steps and long-term Next steps plan


strategy

You might also like