Generally, executive management looks to the chief information security officer (CISO) or other senior cybersecurity
manager to define the information security program and its subsequent management. Often, the cybersecurity
manager is also expected to provide education and guidance to the executive management team. As opposed to
being the decision maker, the manager’s role in this situation is often constrained to presentation of options and key
decision support information. In other words, the cybersecurity manager acts as an advisor.