Related Posts
How is work life balance at Citi Risk Team?
I work at HCL as a Pre sales consultant which involves technical understanding and being in touch with latest technologies, I have got an offer from Genpact Bid Management team which I heard offer BPO services, should I join or stay in a techno functional role and how is the bid Management department in Genpact Genpact HCL Technologies
Bid Management Pre Sales
Any insight into STB’s tax group?
Any comparison of M&A in practice vs in-house?
More Posts
Anyone working in Pharma industry?
Legit excuse to cover moonlighting 🤣

Additional Posts in Cyber Security Bowl
Anyone working in Pharma industry?
Any tips or tricks for CSX certification?
New to Fishbowl?
unlock all discussions on Fishbowl.



Implementation of controls per NIST CSF and other best practices is the responsibility of the CISO, auditing the information security controls based on NIST CSF is the IT auditor’s responsibility.
If you have a traditional 3LoD model then:
Design of controls and assurance of their operation would be the CISO (a 2nd line)
Implementation of the controls and monitoring of their performance would be operational and the CIOs responsibility (1st line)
Assurance for both would be done by the Auditor (3rd line).
If they chose to base some of that on a framework like CSF then all the roles can fit in there.
Sounds like it depends on the org.
Most of the time, it does sound like IT Auditors typically drives the NIST CSF audit and CISO is a key player in their interviews.
CISO takes the NIST CSF framework guidance though and uses it to drive security program activities.
Exactly
Both
CISO
And if they’re astute enough, a 3rd party advisor assists to reduce the internal friction. 😉