Feb. 17, 2023, 1:59 a.m. | /u/eldergrapple

cybersecurity www.reddit.com

CIO/CISO conflict of interest scenario...

The CIO tries to coerce the CISO (who reports to the CIO) to use their incident reporting process to censure and intimidate another department's senior staff -- by misrepresenting a minor issue that wouldn't normally meet the reporting threshold.

​

How would you describe the ethical boundary being crossed? How should the CISO respond?

amp cio ciso coerce conflict conflict of interest cybersecurity department ethics incident incident reporting interest issue process reporting reports respond scenario staff

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Cybersecurity Triage Analyst

@ Peraton | Linthicum, MD, United States

Associate DevSecOps Engineer

@ LinQuest | Los Angeles, California, United States

DORA Compliance Program Manager

@ Resillion | Brussels, Belgium

Head of Workplace Risk and Compliance

@ Wise | London, United Kingdom