The CISO Role Within U.S. Federal Government Contracting Organizations: A Delphi Study

This dissertation examines the role of the Chief Information Security Officer within organizations that support the U.S. federal government. I completed the research as part of my Doctor of Information Technology degree at Capella University in 2020.

The research addresses a specific problem within the federal contracting community: organizations are increasingly dependent on digital systems while also being required to meet expanding federal cybersecurity requirements. Failure to manage those requirements can affect security, resiliency, and an organization’s ability to compete for and maintain federal contracts. The study examined how the CISO should be positioned and used within these organizations to manage that risk while supporting the mission and business objectives of the company.

I used a qualitative classical Delphi methodology and brought together 19 cybersecurity leaders with direct experience supporting federal government contracting organizations. Across three rounds of research, the expert panel worked toward consensus on the responsibilities of the CISO, the meaning of those responsibilities, and where the CISO should sit within the organizational structure.

The research identified five themes that consistently defined an effective CISO within this environment: business alignment, program management, risk management, architecture, and security requirements. Business alignment and program management were the two most frequently identified themes across the study.

The expert panel also ranked nine critical CISO roles. Risk Management was ranked first, followed by Strategy and Planning, Business Partner and Integrator, Governance and Compliance, Security Knowledge, Security Program Management, Communications and Marketing, Technical Security Operations, and Security Architecture.

One of the more significant findings involved organizational placement. The study found strong support for the CISO reporting directly to the CEO. Sixteen of seventeen respondents supported that relationship to provide transparency around cybersecurity and technology risk. Reporting to the CIO was considered viable when the CIO reports directly to the CEO, actively champions cybersecurity, and ensures that cybersecurity risk reaches executive leadership without being filtered.

The research presents the CISO as much more than the leader of a technical security function. Within a federal contracting organization, the CISO must combine cybersecurity knowledge with risk management, business strategy, program leadership, communication, architecture, compliance, and organizational change. The result is a model for positioning cybersecurity as part of how the organization operates, manages risk, protects federal information, and maintains its ability to support the federal mission.

Discover more from DrDeathLabs

Subscribe now to keep reading and get access to the full archive.

Continue reading