From Risk To Trust Volume 4

The Applied CISO Reference - AI, Resilience, Third-Party Risk, Unified Controls, and CISO Playbooks

Lead the work when the pressure is real.

AI is already in use. An incident is underway. A critical dependency sits outside your control. From Risk to Trust, Volume IV - The Applied CISO Reference turns uncertainty into decisions, ownership, action, and evidence.

Designed to stand on its own, this final volume connects AI governance and threat response, security operations and resilience, third-party assurance, unified controls, and practical CISO playbooks - twenty-seven chapters in five parts.

Part 1 - AI, LLM, and emerging technology risk. Govern AI against the NIST AI RMF, ISO 42001, and the EU AI Act. Map the AI and large language model threat surface, put governance into practice, and operate it through red-teaming, monitoring, and AI incident response.

Part 2 - Security operations, resilience, and crisis management. Threat-informed operations. An incident response plan and team that hold under load. Tabletop exercises and ransomware readiness. Crisis communication, forensics, and regulatory notification. Business continuity, disaster recovery, and backup strategy.

Part 3 - Third-party, customer, and supply chain assurance. The vendor risk lifecycle from onboarding to offboarding. SaaS, outsourcing, and fourth-party exposure. Contracts, right to audit, and continuous monitoring. And the other side of the desk, where you answer customer due diligence and security questionnaires.

Part 4 - One unified control framework. Build a single control taxonomy and mapping methodology, then map ISO 27002, NIST SP 800-53, SOC 2, PCI DSS, CIS Controls, and CSA CCM against it. Integrate privacy, AI governance, and sector regulation. Trace policy to control to evidence in one assurance model, so audit readiness is a state you maintain rather than a scramble on someone else's clock.

Part 5 - CISO playbooks, metrics, templates, and interview readiness. Board and risk reporting templates. The control library and policy index. Audit, evidence, and readiness checklists. The CISO 30/60/90 plan and interview readiness. Consulting and advisory use cases. Cyber insurance and claim readiness. Mergers, acquisitions, and divestitures.

Every chapter sets out the evidence you should expect to see, and closes with what it means for you as a security leader. Frameworks anchor the work. They never replace it.

Written for CISOs, security leaders, GRC and assurance professionals, risk owners, auditors, architects, technology leaders, and advisors - with or without the title.

Many frameworks, one operating model. One line of proof.

Risk is what you govern. Trust is what you earn.

September 2026, ca. 554 Seiten, Vikas Khandelwal, Englisch
Independently Published
978-93-344-8519-6

Weitere Titel zum Thema