How to plan your own professional information security

Career planning of information security personnel

Suppose you are a fresh graduate, there are only two ways.

superincumbent

and

from below

party

Type,

But anyway,

At this time, you can't even stand at a high angle.

Because you lack knowledge and experience.

Testing.

from below

Starting from the technology of security companies, it gradually transits from network security to information security.

superincumbent

Start with the Big Four or consulting companies, and take the consulting mode from the beginning. But I think most of them are

I started out as a technician.

Assuming that vocational skills are graded, I think they can be roughly divided into several categories:

Strategic vision

-

operate

-

Technology (technology management)

Technical things are actually easy to learn. Operating system, network, database, etc. Nothing more than copying and learning.

Spend some time on self-study in life, even if you dare not master it.

(If your level exceeds the average level of employees.

Ping, you

You can use proficiency, and the level of proficiency does not depend on your age at all, nor does it depend on your working hours.

The length of)

Just be familiar with it. Information technology outside the computer platform can touch information security.

I will study when I am at school.

It doesn't matter, after all, the big head of information security is computer network communication. If you put this

It's hard to think, so it must be "difficult" to learn.

If you don't take these as anything, then learn them.

It's easy to get up naturally.

very

In layman's view, it is mostly the role of Daniel.

If used objectively

"knowledge ability"

If you measure it, you won't worship blindly.

I personally think

CISSP

In fact, the content does not belong to management.

More is technical management or technology.

Category.

If it goes faster,

The technical foundation can be completed in the student days.

After work, I mainly contact some.

Enterprise operation system, understand various industries.

information technology

How does the system support business operations and understand the organizations in the enterprise?

Structure, roles and functions.

while

When trying to transition to information security management, you must first change your perspective, not always.

Look at and solve problems from a technical point of view everywhere. These international safety standards and

information technology

Best governance

Learn from practice.

It's not difficult at all. The difficulty lies in not knowing enterprise management, operation and operation.

industrial

information technology

If we insist on mechanical access because of the characteristics of the system, we will find a big knowledge loophole.

Many people's careers.

"death"

When the viewing angle cannot be switched,

You can't look at the problem from a higher angle.

Of course, it is understandable to like to do technology.

After the transition from ordinary technicians to consultants,

I am about to face the first bottleneck of my career.

first

One option is to work for Party A..

Computer service office (Computing Services Office)

A large company with a mature management system may have the following positions:

Chief risk officer,

cathode ray oscillograph

Chief security officer,

Central Bureau of Statistics /CISO

Chief security officer,

Naval master sergeant

Director of internal audit

cathode ray oscillograph

In fact, the director of risk management mainly manages financial risks.

information technology

Risk is only second, so is technology.

It is almost impossible for a person with a surgical background to be qualified for this position.

Computer service office (Computing Services Office)

Director of information security, the most frequent and most likely position.

On the other hand, we should set up a separate risk in China.

/

There are not many enterprises with safety management positions, and they are generally listed overseas.

In order to meet the governance compliance requirements of foreign laws and regulations,

Or on a large scale,

Risk and information control

More sensitive enterprises.

If your position in the organizational structure of the enterprise is far from the governance level of best practices, you will not be able to exert your hands and feet.

If you can't do anything, please contact the headhunter to jump ship.

Computer service office (Computing Services Office)

We should not only be proficient in information security technology, but also understand management and business, although there are always people trying to do so.

I express how competent a skilled safety manager is, in fact, technology is not the first.

Including how to establish with the help of international standards.

International symposium on morphology

Methodology and so on are relatively simple things, right?

Computer service office (Computing Services Office)

take for example

The most important ability to work successfully in an organization is

emotional quotient (EQ)

A career development is industry transformation,

For example, go to Party A to do it.

Computer service office (Computing Services Office)

You can change yourself into any industry,

Another career development is career transformation, for example, from pure safety management to.

information technology

Governance and risk management

Management, even financial risk management, completely changed the nature, content and nature of their work.

let

There will be an upper limit for any industry and any career development. An "example" is bound to accompany.

A kind of "result"

. If you choose a certain path, the result is close. most

After working for many years

Complaining about losing room for growth is actually due to lack of planning and narrow vision. in fact

There is no need to complain,

Because the outcome of this stage can be predicted in advance,

Everyone must be right

One's own choice bears the responsibility.

Fruit. Before choosing this road, you should know where this road leads!

Although the global informatization trend is unstoppable, it has also created a lot.

information technology

Enterprises also provide a large number of social.

scalar

information technology

as soon as...

Career opportunities. But I don't like those narrow ones.

information technology

Location. Although people often say that all roads lead to Rome

Rome,

But in fact, with the different capital accumulation speed and demand ability of different industries,

Potential hint

Different industries still

There are high and low, just like

Computer service office (Computing Services Office)

Never with

Chief Finance Officer (CFO)

On a par. such as

If you think the industry is too easy to "head"

Then it is necessary to try to change majors. From the perspective of information security

It is more obvious to the industry.

The way out is to find a consulting company with "face" and try it yourself.

MBA+

Self-study complete financial and financial knowledge, by

information technology

Risk management turns to real enterprise management consulting or finance.

Service consultation, the way out in the future.

It may be wider. This model can regenerate a huge professional hair.

Show the tree, but stop here.

Practitioners who focus on the technology itself,

The way out won't be great.

Although entrepreneurship also has a blue ocean,

but

Blue ocean

size

For this industry, its scale is very small.

The Red Sea is a contested mess.

And your growth rate will determine whether you can survive in the only remaining blue ocean.

reach

Party A's words,

Computer service office (Computing Services Office)

Is it over? Not exactly,

Computer service office (Computing Services Office)

Can continue to be

Congress of industrial organizations.

The key is ...

Because of their own ability accumulation and role change.

if

Congress of industrial organizations.

Become a reformer to promote a substantial increase in profits,

submerge

exist

promise

CGO

(

G

grow

)

And then become

chief operating officer

even

chief evecutive officer

It's all possible, if not.

For changers, or

Congress of industrial organizations.

Only limited liability status is not high, then

Congress of industrial organizations.

Career.

Will be here

Stop.

Self-growth and environmental choice are internal factors,

Career development also depends on another external cause:

The society you have.

Resources and your ability to integrate resources.

There is no end to learning,

It is necessary to recharge at any time to improve your ability and vision.

The important thing is that the knowledge you have learned will not depreciate because the company does not pay attention to it, and the social needs determine your value.

The use of time is like investment, which must be considered: opportunity cost, investment portfolio, return on income and risk. you

Today, I embarked on this career development path.

There is no time to go the other way.

Are you in the slow lane or the fast lane?

Expressway or by plane? If this road

A

Failure, how will you continue to develop, etc. ...

Some examples are given in this paper,

In fact, it means that any industry,

Any profession has career reengineering,

Secondary force

This possibility.

strategic

Career planning

Transfer the focus of one's knowledge and ability in a planned way,

Beyond occupation

Be imprisoned, unconventional, and do interesting and challenging things.

The road is either wider or narrower. Many people feel that there is no turning back because they just don't want to go.

I lost my watermelon a few years ago to pick up the sesame seeds in front.

The direction in which most people flock is often empty.