|
|
|
|
|
by andrewstuart
2580 days ago
|
|
Maybe this concept should just get rid of the CTO aspect and position it as the "SaaS security checklist". Then gamify it so that all the technical people in the team can each give their independent rating of how the company performs on each checklist item. Then give each checklist item and owner and assign action items, status and followup discussion. The outcome of that is something the CTO would be interested in because it would be a dashboard with accountability. |
|
We wrote this for CTOs since prior to hiring a dedicated security engineer, security responsibilities in a company often fall to the CTO. But really, any more technical person in a company with some ownership or interest in security can leverage this.