Security1 distinct publisher3 min readUpdated
An SC World decision guide argues the CISO "authority gap" is a category error, and that the fix is assigning each high-consequence decision to a named owner rather than handing the CISO more power.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
An SC World decision guide argues the CISO "authority gap" is a category error, and that the fix is assigning each high-consequence decision to a named owner rather than handing the CISO more power.
A practitioner decision guide published by SC World argues that the standard complaint about the CISO role - responsibility for security outcomes without the authority to control them - is the wrong diagnosis [1]. That matters because the usual remedy, more authority for the CISO, leaves the people actually making risk-bearing decisions exactly where they were [2].
The guide's central point is uncomfortable and correct. Security outcomes are produced by product owners, infrastructure teams, procurement committees, application developers and line-of-business leaders [3] - five distinct populations, none of whom report to the security function in most organisations [18]. Naming the CISO as the accountable party for all of it does not assign accountability; according to the guide, it creates a liability shield for everyone else [4]. Risk-bearing decisions keep being made by people who carry no formal accountability, while the CISO carries accountability for decisions they did not make and cannot unilaterally reverse [5].
The reason this passes unnoticed is a confusion about control functions. The CISO runs the security programme, so the CISO is assumed to own the outcome of security-relevant decisions made by others [6]. The guide argues that inference turns operationally dangerous when it starts shaping escalation paths, budget authority and post-incident reviews [7]. The question to ask is not how to make the CISO more powerful but who owns each decision, and how the organisation knows [8].
Underneath that sits a vocabulary problem. Accountability means being answerable for the result, responsibility means doing the work, and authority means being able to commit resources or block action [9]. Collapse them and the failure modes are predictable: accountability without authority is exposure, responsibility without accountability produces drift, and authority without accountability produces unchecked risk-taking [10]. The guide notes this is not new theory - NIST SP 800-39 already distributes risk management across the organisation, mission/business-process and information-system tiers and defines a risk executive function [11], and the Govern function in NIST Cybersecurity Framework 2.0 establishes cybersecurity roles, responsibilities and authorities while treating oversight as distinct from executing controls [12].
The operational test is granularity. A decision-rights model maps each high-consequence security decision to a named role owner, not a team name, not a committee, and not "the business", on the grounds that named owners can be held to SLAs and committees cannot [13]. The guide identifies four decision types that recur in breakdowns: implementing a threat-informed control, remediating a known exposure within an agreed SLA, approving a high-risk change to a payment or production system, and formally accepting residual risk on behalf of the organisation [14]. In that model the CISO holds process oversight and escalation authority rather than default ownership [15]. The blunt version: a CISO who owns every decision owns every failure [16].
What to watch is the enforcement edge, which is where these models usually die. Decision rights fail when declining to decide carries no consequence - if a product owner can defer a critical remediation indefinitely without triggering formal escalation, the table on the wall is decorative [17]. Two artefacts tell you whether an organisation has actually done this: residual-risk acceptances signed by a named business owner rather than the security team [14][13], and post-incident reviews that name the decision owner instead of the control function [7][15].
Ranked by verification strength, evidence, and original report placement.
A common criticism of the CISO role is that CISOs are held responsible for security outcomes without having the authority to control the decisions that produce them; the SC World guide argues this framing is the wrong frame and a category error rather than a gap.
Simply giving the CISO more authority does not solve the underlying problem.
Security outcomes are the product of decisions made by product owners, infrastructure teams, procurement committees, application developers, and line-of-business leaders.
When the CISO is named the accountable party for all of those outcomes, the organization has not assigned accountability; it has created a liability shield for everyone else.
Risk-bearing decisions continue to be made by people who carry none of the formal accountability, and the CISO carries accountability for decisions they did not make and cannot unilaterally reverse.
Leaders underestimate this because the CISO role is framed as a control function, and control functions feel like ownership: the CISO controls the security program, so the CISO is assumed to own the outcome of security-relevant decisions made by others.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Coherent argument, single source, no primary or empirical backing
Every claim traces to one practitioner guide from one publisher. The internal reasoning is consistent and the two standards invoked (NIST SP 800-39's tiered risk management and risk executive function, CSF 2.0's Govern function) are real anchors, but both are characterized second-hand with no primary document in the cluster, and the one frequency claim about recurring breakdown decision types carries no data. Nothing here is falsifiable against outside evidence as supplied.
No adoption signal in cluster
The cluster contains no deployment, release, usage disclosure, survey, or named organization implementing a decision-rights or shared-accountability model. No adoption observations could be recorded without inventing facts.
Confident prescription running ahead of demonstrated practice
The guide's assertions are stated with high certainty — the accountability gap is a 'category error', sole CISO accountability is a 'liability shield', named ownership is 'more defensible and more effective', the model is 'not novel theory' — while the cluster shows no implementation, no outcome measurement, and no engagement with legal or regulatory duties that may attach to the CISO regardless of internal decision rights. The overstatement is modest rather than promotional: there is no product, vendor, or commercial claim being inflated, only normative confidence exceeding supplied evidence.
Trade-press practitioner-guide franchise, no disclosed commercial tie
The item is published under scworld.com's 'practitioner-decision-guide' path, a format built to serve security-leadership readership and the surrounding trade-media business; that creates an incentive toward confident, framework-shaped prescriptions and CISO-sympathetic framing. Offsetting this, the cluster discloses no vendor sponsorship, product placement, or named commercial beneficiary, and the argument does not sell a tool.
Argument reliably captured, real-world validity unverified
Confidence is high that the claims accurately represent what this guide argues — the text is explicit and internally consistent. Confidence is low that the prescriptions hold in practice: one publisher, no corroboration, no primary standards text, no adoption evidence, and no contesting voice on whether distributed decision rights survive contact with regulatory or legal accountability regimes.
Follow any of these and your For You feed starts watching them — no settings page required.
build
If two people cannot reproduce the number, the dashboard is decoration1 distinct publisher
build
Hybrid Post-Quantum TLS: Same Protocol, a 1,216-Byte Key Share1 distinct publisher
security
50,000 Findings Is Not A Result: Score DSPM On Closure Rate1 distinct publisher
science
NIST's own logs show agents looking up the answers, making public benchmark scores soft evidence1 distinct publisher