ISA and the National Association of Corporate Directors (NACD) have coauthored the Director’s Handbook for Cyber-Risk Oversight since its inception. This handbook contains the only set of cyber best practices that have been independently assessed (by PwC, the World Economic Forum and MIT) and found to produce significant improvements in cybersecurity, including better cyber risk management, better alignment between cybersecurity and business goals, and helping to create a culture of security while reducing cyber incidents by 80%.
There are now a half dozen adapted versions of these handbooks available in 5 languages on four continents! ISA adapts and translates these handbooks in partnership with government and board-level institutions around the world including the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the European Conference of Director Associations, the German Federal Office of Information Security (BSI), the OAS, and others. ISA has also produced a companion book, Cybersecurity for Business: Ensuring Cyber Risk is NOT Just an IT Issue, which coordinates the board level principles and toolkits in the Handbooks with cyber operational practices for the management team.
In 2014, NACD published the first edition of the Cyber-Risk Handbook in conjunction with the ISA and AIG. In 2017, ISA and NACD released an updated second edition. New editions of the Cyber-Risk Handbook generally come out every 3 years. In April 2018, ISA and NACD cohosted a Global Summit on Cybersecurity for corporate boards in Geneva. The goal of this event was to create a coherent approach to cybersecurity based on the Handbook’s principles but adapted to unique environments outside the United States. The ISA also held workshops in the United Kingdom and Germany to prepare local versions of the handbook, which were published in 2018.
NACD helps more than 17,000 directors lead with confidence. As the recognized authority on leading boardroom practices, NACD aspires to a world where businesses are sustainable, profitable, and respected, and where stakeholders trust directors to develop strategies that create long-term value and provide effective oversight.
Arne Schönbohm, president of the German Federal Office for Information Security (BSI), and the Internet Security Alliance have been collaborating since 2014. BSI is the German government office in charge of computer and communication security. ISA and BSI, in collaboration with the NACD and the International Association of Privacy Professionals, plan to develop a Cyber-Risk Oversight Handbook designed specifically to assist German corporate boards to analyze cybersecurity issues from an enterprise-wide perspective.
Schönbohm and the ISA first collaborated when the former was head of the Cyber Security Council of Germany (CSCG). At the time, the organizations agreed to develop mutual projects to improve cybersecurity and jointly advocate for pro-growth and pro-innovation policies, leading to a sustainable worldwide system of cybersecurity.
The European Confederation of Directors Associations (ecoDa) acts as a European Voice of Directors. ISA partnered with ecoDa to produce a pan-European version of the NACD Cyber-Risk Oversight Handbook for corporate boards of directors. The second edition of this Handbook was published in September 2024.
ecoDa is a think tank with forward-looking approach to the role of tomorrow’s boards. To accomplish this, ecoDa remains alert to new trends, developing best practices and excelling directors’ professionalism towards value adding boards. Headquartered in Brussels, the organization is proactive on the European Commission’s agenda and policymaking. EcoDa cooperates with different stakeholders on key CG issues and allows us to communicate our positions towards EU institutions and jointly organize different conferences, webinars and events. EcoDa is a European platform of directors.
Keidanren USA is the U.S. liaison entity for Keidanren, the Japan Business Federation. Keidanren is a comprehensive Japanese economic organization with a broad membership consisting Japanese companies, industry associations, and regional economic organizations. Keidanren USA’s office is located in Washington, D.C. Its core mission is to facilitate increased engagement between the Japanese business sector and the U.S. policymaking community, as well as to promote the real Japanese contributions (in terms of investment and jobs) to the U.S. economy.
ISA partnered with Keideren in 2019 to produce a Cyber-Risk Oversight Handbook for Japanese Boards of Directors.
The Organization of American States (OAS) was established in order to achieve “an order of peace and justice, to promote their solidarity, to strengthen their collaboration, and to defend their sovereignty, their territorial integrity, and their independence” for the 35 independent states of the Americas. The OAS constitutes the main political, juridical, and social governmental forum in the Western hemisphere.
ISA partnered with OAS in 2018 to adapt the NACD’s Cyber-Risk Oversight Handbook for Corporate Boards for use by Latin American Boards of Directors.
Cybersecurity and privacy are the twin issues of the digital age. It’s important for cybersecurity professionals (especially those in the European Union and in other places where privacy is intensely regulated) to understand how to accommodate those concerns. The Internet Security Alliance teamed with the IAPP to adapt the Cyber-Risk Oversight Handbook for the unique policy environments found in the United Kingdom and Germany. ISA’s work with the IAPP culminated in April 2018 with a Global Summit on Cybersecurity for corporate boards in Geneva hosted by ISA and the NACD.
In 2001, the Carnegie Mellon CyLab, a world leader in both technological research and the education of professionals in information assurance, security technology, business and policy, as well as security awareness, helped found the Internet Security Alliance. CyLab representatives serve on our Board of Directors and have continued to work with ISA in the ensuing years on many projects and publications. We value their technical expertise.
CyberTrak is a highly innovative online cybersecurity tool featuring information on cybersecurity-related mandates in 23 key markets around the world. This online information tool is available on an annual subscription basis to help general counsels, chief information security officers, chief information security officers, risk officers and legal, technology, IT and procurement departments of multinational companies to make better risk management decisions by keeping up with cybersecurity-related laws, regulations and standards around the world. ISA partnered with DLA Piper, a global law firm with lawyers located in more than 30 countries throughout the Americas, Europe, the Middle East, Africa and Asia Pacific, in the development of CyberTrak.
The American National Standards Institute (ANSI) empowers its members and constituents to strengthen the U.S. marketplace position in the global economy while helping to assure the safety and health of consumers and the protection of the environment. The Institute oversees the creation, promulgation and use of thousands of norms and guidelines that directly impact businesses in nearly every sector. ISA and ANSI continually work on joint projects and publications.
The National Association of Manufacturers is the largest manufacturing association in the United States, representing small and large manufacturers in every industrial sector and in all 50 states. NAM is the powerful voice of the manufacturing community and the leading advocate for a policy agenda that helps manufacturers compete in the global economy and create jobs across the United States.
The U.S. Chamber of Commerce is the world’s largest business organization representing the interests of more than 3 million businesses of all sizes, sectors, and regions. Members range from mom-and-pop shops and local chambers to leading industry associations and large corporations. ISA and the U.S. Chamber continue to work together on publications for cybersecurity issues in businesses.
GEC Risk Advisory is a global strategic governance, risk, cyber, reputation and crisis advisor to boards, executives, investors and advisors, in multiple sectors including financial, pharmaceutical, utility, technology, research, non-profit and governmental. Specialties include strategic risk and opportunity, reputation risk and resilience building; cyber-risk governance; crisis management; global anti-corruption and supply chain; and Transforming Risk into Value workshops. Our focus is on delivering constructive, multicultural, strategic and business-savvy advice aimed at improving stakeholder trust and enterprise value.
Enter your email to be added to our email list: