Artifacts
3 of 9 artifacts published
Foundations
0/3Annotated bibliography of 15 selected sources prepared for the Georgia Tech MS Cybersecurity program. Sources span foundational organizational theory (strategic alignment, boundary spanning), authoritative governance frameworks (NIST CSF 2.0, COBIT, NIST SP 800-39), analyst research on cybersecurity leadership scaling, and the emerging body of BISO-specific literature.
Pending — full content will be published as research progresses
Structured matrix mapping 15+ sources to the working thesis. Each source is evaluated across core argument, relationship to the thesis (supports or challenges), and connection to the BISO governance intermediary model. Sources span organizational theory, governance frameworks, cybersecurity leadership evolution, and BISO-specific literature.
Pending — full content will be published as research progresses
Formal research proposal outlining the study's purpose, problem statement, research question, theoretical framework, and methodology. Argues that the BISO should be understood as a governance intermediary rather than a communication function, and positions the research contribution relative to existing literature.
Pending — full content will be published as research progresses
Analysis
2/2Raw practitioner observations and three case studies documenting real BISO governance scenarios. Covers role perception, security-business communication dynamics, governance process challenges, and recurring patterns across conflict resolution cases involving compensating controls, exception management, and administrative access decisions.
Twelve working theories emerging from literature review and practitioner observations. Documents the evolution of the governance intermediary thesis, an emerging conceptual model, practitioner themes, and areas requiring further validation. Version 2 reflects a refined framing of the BISO as a governance intermediary rather than primarily a communication function.
Field Work
1/3Structured template for documenting and analyzing individual practitioner interviews. Captures interviewee background, key themes, notable quotes, evidence supporting or challenging the working thesis, newly identified themes, and follow-up questions. Used consistently across all interviews to support systematic qualitative analysis.
Semi-structured interview guide for practitioner interviews. Five core questions covering security-business conflict, risk acceptance decision-making, the role of trust, BISO value and function, and the future of cybersecurity-business governance. Includes role-specific follow-up prompts for executive, cybersecurity, GRC, business, and communications leaders.
Pending — full content will be published as research progresses
Candidate pool of eight practitioners identified for interview. Represents six functional perspectives: executive technology leadership, cybersecurity leadership, governance and risk, security partnership, business leadership, and communications. Each candidate is documented with primary research value and anticipated thematic contribution.
Pending — full content will be published as research progresses
Writing
0/1Proposed structure for the final research paper. Covers the evolution of cybersecurity leadership, the governance intermediary framework, literature review across seven sub-areas, conceptual framework, mixed methodology, findings organized by theme, and implications for cybersecurity leadership and NIST CSF governance.
Pending — full content will be published as research progresses
