

vCISO
First Row's Virtual Chief Information Security Officer (vCISO) service provides strategic cybersecurity leadership and guidance to organizations; including developing and overseeing an organization's overall Information Security Program that protects the organization's data, systems, and assets from threats and ensure compliance with relevant regulations.
The Compliance and Certification Service and Documentation Service are subsets of the vCISO service; those services can be included in the selected vCISO Service Subscription Level.
vCISO Responsibilities
Governance, Risk, and Compliance
Manage Security Policies and Procedures
Oversees and Manages Compliance
Leads Security Certification Initiatives
Leads Selection of Third Party Assessor
Security Assessor-Facing Focal Person
Incident Response
Manage the Incident Response Plan
Lead Incident Response Exercises
Manage the Disaster Recovery Plan
Lead Disaster Recovery Response Exercises
Security Reviews
Review and Respond to Customer Requests
Review/Update Security Policies and Procedures
Review/Update Security Plans
Review Vendor Security Documentation
Cross-Functional Team Reviews
Risk Management
Manage the Risk Management Program
Assign Risk Impact Scores to Risks
Manage the Risk Register
Lead Risk Register Reviews
Lead Risk Assessment
Responsibility Matrix
All Services come with a subscription level defined Responsibility Matrix to document responsibilities of the vCISO, the business, and joint-responsibilities. The vCISO Responsibility Matrix is standard, but can be adjusted on a case-by-case basis to satisfy the business needs as part of the Custom-Designed Service option.