Olivier Caleff is a CISO (Cyber-Resilience & Crisis Director) at ERIUM as well as a Member of Board of Directors at FIRST. He is very well familiar of both perspectives – being a CISO and part of a CSIRT/SOC. We asked Olivier to consider the pros and cons of CSIRT/SOC for a CISO and here are his thoughts and insights.
Below Olivier expands on the 3 topics:
Everything must be defined in advance. It starts with the type, quality, and frequency of data delivery, then the procedures and various communication channels: one for standard in-band communications, and at least one out-of-band or if additional security requirements must be enforced, e.g., in terms of confidentiality.