Skills you think a CISO should have?

I want your opinion on what you think a Chief Information Security Officer (CISO) should know/have in terms of experience, knowledge, skills, education, etc.
There is no right or wrong answer, and I'll share my own answer in a bit.
The reason I ask this is because I see so many odd opinions on LinkedIn with regards to what a CISO need to know/be. I've seen bizarre things like a CISO should be a certain gender or has to come from law enforcement or other nonsense, so let's have a healthy discussion on the skills and knowledge/experience that makes up great CISOs
Certs: GSTRT, GPEN, GCFA, CISM, CRISC, RHCE
Check out my YouTube channel: https://youtu.be/DRJic8vCodE
Tagged:
Comments
But, also a strong business background, possibly with an MBA (or some business degree). Many decisions are based on the needs of the business. You could spend a ton of money on a problem and it'll work. You could also see that it wouldn't help the business one bit (risk management as well as actual business needs). It is also huge in talking with other executives, most of which don't speak the technical jargon. They want to know how it will affect their bottom line and how it does benefit the business (or minimize the harm done if there is significant risk and they are breached in case they do nothing). Having a bit of accounting knowledge helps a lot, too. Will that layer 9 synergestic firewall content filtering cloud based appliance have a good ROI, or will it just be another thing for your guys to manage without really doing anything? Being the liaison between the technical teams and the management teams.
Gender? Nope. Law enforcement? Nah, but a bit of that kind of knowledge does help out.
Just my thoughts, anyway. Probably a lot I missed or got wrong, but those are what I'd like to see in a CISO. Well rounded, good with technical stuff but focused on the business.
Connect With Me || My Blog Site || Follow Me
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
Forum Admin at www.techexams.net
--
LinkedIn: www.linkedin.com/in/jamesdmurray
Twitter: www.twitter.com/jdmurray
I think that is a succinct way to put it. +1!
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?