Skip to main content
Tradecraft Labs
BISO GovernanceActive

The Business Information Security Officer as a Governance Intermediary: Improving Cybersecurity Decision Quality Through Trust, Influence, and Risk-Based Decision Making

Current Stage: Interviews

Research Question

"How does the Business Information Security Officer function as a governance intermediary and boundary-spanning leader to improve the quality of cybersecurity risk decisions between business and security stakeholders?"

Working Thesis (v2)

The Business Information Security Officer (BISO) functions as a governance intermediary and boundary-spanning leadership role that enables organizations to navigate competing cybersecurity and business priorities through structured risk-based decision making. Its effectiveness is determined less by technical authority and more by its ability to facilitate governance processes, improve decision quality, establish stakeholder trust, and influence organizational risk decisions.

This thesis evolves as research progresses.

Project 001 is the foundational research initiative for Tradecraft Labs. It examines the Business Information Security Officer role through the lens of organizational governance theory, boundary-spanning leadership, and enterprise risk management, rather than through the narrower lens of security operations or communication function.

The research draws on academic literature across strategic alignment, governance facilitation, and decision rights theory, combined with practitioner interviews from cybersecurity, business, and governance leaders.

Artifacts

View all →

Foundations

0/3
Annotated Bibliographyv1

Annotated bibliography of 15 selected sources prepared for the Georgia Tech MS Cybersecurity program. Sources span foundational organizational theory (strategic alignment, boundary spanning), authoritative governance frameworks (NIST CSF 2.0, COBIT, NIST SP 800-39), analyst research on cybersecurity leadership scaling, and the emerging body of BISO-specific literature.

Pending — full content will be published as research progresses

Literature Matrixv1

Structured matrix mapping 15+ sources to the working thesis. Each source is evaluated across core argument, relationship to the thesis (supports or challenges), and connection to the BISO governance intermediary model. Sources span organizational theory, governance frameworks, cybersecurity leadership evolution, and BISO-specific literature.

Pending — full content will be published as research progresses

Research Proposalv1

Formal research proposal outlining the study's purpose, problem statement, research question, theoretical framework, and methodology. Argues that the BISO should be understood as a governance intermediary rather than a communication function, and positions the research contribution relative to existing literature.

Pending — full content will be published as research progresses

Analysis

2/2

Raw practitioner observations and three case studies documenting real BISO governance scenarios. Covers role perception, security-business communication dynamics, governance process challenges, and recurring patterns across conflict resolution cases involving compensating controls, exception management, and administrative access decisions.

Twelve working theories emerging from literature review and practitioner observations. Documents the evolution of the governance intermediary thesis, an emerging conceptual model, practitioner themes, and areas requiring further validation. Version 2 reflects a refined framing of the BISO as a governance intermediary rather than primarily a communication function.

Field Work

1/3

Structured template for documenting and analyzing individual practitioner interviews. Captures interviewee background, key themes, notable quotes, evidence supporting or challenging the working thesis, newly identified themes, and follow-up questions. Used consistently across all interviews to support systematic qualitative analysis.

Interview Guidev1

Semi-structured interview guide for practitioner interviews. Five core questions covering security-business conflict, risk acceptance decision-making, the role of trust, BISO value and function, and the future of cybersecurity-business governance. Includes role-specific follow-up prompts for executive, cybersecurity, GRC, business, and communications leaders.

Pending — full content will be published as research progresses

Interview Poolv1

Candidate pool of eight practitioners identified for interview. Represents six functional perspectives: executive technology leadership, cybersecurity leadership, governance and risk, security partnership, business leadership, and communications. Each candidate is documented with primary research value and anticipated thematic contribution.

Pending — full content will be published as research progresses

Writing

0/1
Paper Outlinev1

Proposed structure for the final research paper. Covers the evolution of cybersecurity leadership, the governance intermediary framework, literature review across seven sub-areas, conceptual framework, mixed methodology, findings organized by theme, and implications for cybersecurity leadership and NIST CSF governance.

Pending — full content will be published as research progresses