Award

Enterprise CISO Council and Risk Heat Mapping Initiative

Executive Summary

As government operations become increasingly dependent on mission-critical digital services, the Commonwealth recognized the need for a unified enterprise approach to identifying, assessing, and prioritizing risk. Historically, agencies managed cybersecurity and operational risk independently, resulting in inconsistent methodologies, limited enterprise visibility, and challenges communicating operational impact to executive leadership.

To address these challenges, the Commonwealth re-oriented and strengthened its Enterprise CISO Council composed of Secretariat-level CISOs, risk and security leaders. The Council created a standardized framework to identify critical business applications and government assets while assessing associated security, technology, and operational risks through enterprise risk heat maps.

Since implementing the strategy, the Commonwealth has achieved enterprise-wide participation across Secretariat organizations, standardized risk terminology and scoring methodologies, completion of agency-level risk heat maps, improved identification of critical business assets and operational dependencies, and greater executive engagement in cybersecurity and operational risk management. The initiative established a sustainable governance model supporting continuous reassessment of emerging risks and enterprise resilience priorities.

Related Awards