<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=CISO_Survey_2013%3A_Executive_Summary</id>
		<title>CISO Survey 2013: Executive Summary - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=CISO_Survey_2013%3A_Executive_Summary"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=CISO_Survey_2013:_Executive_Summary&amp;action=history"/>
		<updated>2026-04-19T21:20:47Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=CISO_Survey_2013:_Executive_Summary&amp;diff=167596&amp;oldid=prev</id>
		<title>Tgondrom at 21:21, 6 February 2014</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=CISO_Survey_2013:_Executive_Summary&amp;diff=167596&amp;oldid=prev"/>
				<updated>2014-02-06T21:21:22Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 21:21, 6 February 2014&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[OWASP CISO Survey|&amp;lt; Back to the CISO Survey main page]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[OWASP CISO Survey|&amp;lt; Back to the CISO Survey main page]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;__NOTOC__&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;__NOTOC__&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Executive Summary =&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Executive Summary =&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;People often ask us which results of the CISO survey report, we as a fellow CISOs would find particularly interesting and useful. There are many good insights and learning points from this report. And the benefits of it will depend a lot on your own organization’s maturity and security status. For some the overall strategic picture of application security risks and threats is useful to set their security priorities and strategies for next year, for others the list of best practices and recommendations from other CISO peers is particularly useful and others find most valuable to understand which best practices and tools work best for their peers. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;People often ask us which results of the CISO survey report, we as a fellow CISOs would find particularly interesting and useful. There are many good insights and learning points from this report. And the benefits of it will depend a lot on your own organization’s maturity and security status. For some the overall strategic picture of application security risks and threats is useful to set their security priorities and strategies for next year, for others the list of best practices and recommendations from other CISO peers is particularly useful and others find most valuable to understand which best practices and tools work best for their peers. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tgondrom</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=CISO_Survey_2013:_Executive_Summary&amp;diff=167589&amp;oldid=prev</id>
		<title>Tgondrom: wording update</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=CISO_Survey_2013:_Executive_Summary&amp;diff=167589&amp;oldid=prev"/>
				<updated>2014-02-06T21:09:57Z</updated>
		
		<summary type="html">&lt;p&gt;wording update&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 21:09, 6 February 2014&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l4&quot; &gt;Line 4:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 4:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Executive Summary =&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Executive Summary =&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;People often ask us which results of the CISO survey report, we as a fellow CISOs would find particularly interesting and useful. There are many good insights and learning points from this report. And the benefits of it will depend a lot on your own organization’s maturity and security status. For some the overall strategic picture of application security risks and threats is useful to set their security priorities and strategies for next year, for others the list of best practices and recommendations from other CISO peers is particularly useful and others find most valuable to understand which best practices and tools work best for their peers. &lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;People often ask us which results &lt;/del&gt;of the &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;CISO survey report, &lt;/del&gt;we &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;as a fellow CISO would find particularly &lt;/del&gt;interesting and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;useful&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;There &lt;/del&gt;are &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;many good insights &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;learning points &lt;/del&gt;from &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;this report. And the benefits &lt;/del&gt;of it &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;will depend &lt;/del&gt;a &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;lot on &lt;/del&gt;your &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;own organization’s maturity and &lt;/del&gt;security &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;status&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;For &lt;/del&gt;some &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;the overall strategic picture &lt;/del&gt;of application security &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;risks and threats is useful to set their security priorities and strategies for next year, &lt;/del&gt;for &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;others &lt;/del&gt;the &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;list &lt;/del&gt;of &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;best practices &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;recommendations from other CISO peers is particularly useful and others find most valuable to understand which best practices and tools work best for their peers&lt;/del&gt;. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Some &lt;/ins&gt;of the &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;findings &lt;/ins&gt;we &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;found &lt;/ins&gt;interesting &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;to highlight were:&amp;#160; &lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;# Application security risks are clearly on the rise, in absolute numbers &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;also relative to infrastructure security risks&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;# Risks from external threats &lt;/ins&gt;are &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;clearly increasing for organizations.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;# Security awareness and training is the biggest challenge &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;most important priority for CISOs going forward into 2014 (more critical than tools, testing or budget). &lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;# As we hear &lt;/ins&gt;from &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;a number &lt;/ins&gt;of &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;CISOs about difficulties acquiring an adequate budget, &lt;/ins&gt;it &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;appears that having &lt;/ins&gt;a &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;2-year security strategy improves your chances for getting or increasing &lt;/ins&gt;your security &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;budget/investments&lt;/ins&gt;. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;# Only about one fourth of organizations currently have &lt;/ins&gt;some &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;form &lt;/ins&gt;of application security &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;management system or maturity model. But over 40% are looking at this &lt;/ins&gt;for the &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;coming 12 months. So there might be a lot &lt;/ins&gt;of &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;activity in this area in the near future, &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;we hope one of our OWASP projects, openSAMM (Open Software Assurance Maturity Model), can help executives with that&lt;/ins&gt;. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;br&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Some of the things we personally found interesting were:&amp;#160; &lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* Application security risks are clearly on the rise, in absolute numbers and also relative to infrastructure security risks.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* Risks from external threats are clearly increasing for organizations.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* Security awareness and training is the biggest challenge and most important priority for CISOs going forward into 2014 (more critical than tools, testing or budget). &lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* As we hear from a number of CISOs about difficulties acquiring an adequate budget, it appears that having a 2-year security strategy improves your chances for getting or increasing your security budget/investments. &lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* Only about one fourth of organizations currently have some form of application security management system or maturity model - which is pretty low in my humble opinion. But now the good news: over 40% are looking at this for the coming 12 months. So there might be a lot of activity in this area in the near future, and I hope openSAMM (Open Software Assurance Maturity Model), one of our OWASP projects can help executives with that. &lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;br&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Beyond these points, you will find this report contains many more interesting facts and findings and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;I &lt;/del&gt;hope that you will find many of them interesting and helpful for your daily work as a CISO, giving you the right data for defining your security strategies and priorities for the future. We are confident that like 2013, the coming year 2014 will be an interesting year with many challenges in web and application security and hope that we as OWASP can provide you and your organizations with good intelligence and help you with many of our free documentation and tools to manage your security programs better and overall improve application security around the world. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Beyond these points, you will find this report contains many more interesting facts and findings and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;we &lt;/ins&gt;hope that you will find many of them interesting and helpful for your daily work as a CISO, giving you the right data for defining your security strategies and priorities for the future. We are confident that like 2013, the coming year 2014 will be an interesting year with many challenges in web and application security and hope that we as OWASP can provide you and your organizations with good intelligence and help you with many of our free documentation and tools to manage your security programs better and overall improve application security around the world. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:OWASP CISO Survey Project]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:OWASP CISO Survey Project]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tgondrom</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=CISO_Survey_2013:_Executive_Summary&amp;diff=165484&amp;oldid=prev</id>
		<title>Tgondrom: create Executive Summary</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=CISO_Survey_2013:_Executive_Summary&amp;diff=165484&amp;oldid=prev"/>
				<updated>2014-01-06T23:28:49Z</updated>
		
		<summary type="html">&lt;p&gt;create Executive Summary&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[OWASP CISO Survey|&amp;lt; Back to the CISO Survey main page]]&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&lt;br /&gt;
= Executive Summary =&lt;br /&gt;
&lt;br /&gt;
People often ask us which results of the CISO survey report, we as a fellow CISO would find particularly interesting and useful. There are many good insights and learning points from this report. And the benefits of it will depend a lot on your own organization’s maturity and security status. For some the overall strategic picture of application security risks and threats is useful to set their security priorities and strategies for next year, for others the list of best practices and recommendations from other CISO peers is particularly useful and others find most valuable to understand which best practices and tools work best for their peers. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Some of the things we personally found interesting were:  &lt;br /&gt;
* Application security risks are clearly on the rise, in absolute numbers and also relative to infrastructure security risks.&lt;br /&gt;
* Risks from external threats are clearly increasing for organizations.&lt;br /&gt;
* Security awareness and training is the biggest challenge and most important priority for CISOs going forward into 2014 (more critical than tools, testing or budget). &lt;br /&gt;
* As we hear from a number of CISOs about difficulties acquiring an adequate budget, it appears that having a 2-year security strategy improves your chances for getting or increasing your security budget/investments. &lt;br /&gt;
* Only about one fourth of organizations currently have some form of application security management system or maturity model - which is pretty low in my humble opinion. But now the good news: over 40% are looking at this for the coming 12 months. So there might be a lot of activity in this area in the near future, and I hope openSAMM (Open Software Assurance Maturity Model), one of our OWASP projects can help executives with that. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Beyond these points, you will find this report contains many more interesting facts and findings and I hope that you will find many of them interesting and helpful for your daily work as a CISO, giving you the right data for defining your security strategies and priorities for the future. We are confident that like 2013, the coming year 2014 will be an interesting year with many challenges in web and application security and hope that we as OWASP can provide you and your organizations with good intelligence and help you with many of our free documentation and tools to manage your security programs better and overall improve application security around the world. &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP CISO Survey Project]]&lt;/div&gt;</summary>
		<author><name>Tgondrom</name></author>	</entry>

	</feed>