Glossary

vCISO

A vCISO — virtual Chief Information Security Officer — is an experienced security executive engaged fractionally rather than hired full-time. The model exists because companies under a few hundred people need CISO-grade judgment recurringly but not continuously: the roadmap decision, the risk acceptance call, the enterprise security review, the board question.

What a vCISO owns

Beyond framework compliance, a vCISO typically owns the security roadmap, chairs risk decisions, oversees vendor and incident response programs, and represents the security function to buyers, auditors, and boards. The distinction from a consultant is continuity and accountability — an owned outcome rather than a delivered project.

Related Terms

CAIQ — The CAIQ is the Cloud Security Alliance's standard security questionnaire — a yes/no assessment cloud vendors complete once and reuse across customer reviews.

Gap Assessment — A gap assessment maps your current controls against a framework's requirements and produces the remediation plan that makes audit readiness plannable.

SIG Questionnaire — The SIG is Shared Assessments' standardized vendor-risk questionnaire. SIG Core and SIG Lite let buyers assess vendors with one reusable question set.