{"id":1145,"date":"2026-09-10T10:55:13","date_gmt":"2026-09-10T10:55:13","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1145"},"modified":"2026-09-10T10:55:13","modified_gmt":"2026-09-10T10:55:13","slug":"vciso","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/vciso\/","title":{"rendered":"vCISO"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: vCISO (VIRTUAL CHIEF INFORMATION SECURITY OFFICER)\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A vCISO gives you security leadership without a full-time hire: someone accountable for the strategy, the board conversation and the audit, at a fraction of the cost of the role.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Governance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>vCISO stands for virtual chief information security officer. It is a fractional engagement where an experienced security leader owns strategy, roadmap, policy design, audit readiness and incident planning for your company, working part-time across a defined scope. The work is the same as a CISO. The difference is that you are buying judgement by the month rather than a salaried headcount.<\/p>\n<\/div>\n\n<p>The reason the model exists is that the need for security leadership arrives long before the budget for a full-time hire does. A single enterprise deal or a regulator&#8217;s letter can create the requirement overnight.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#does\">What a vCISO does<\/a><\/li>\n    <li><a href=\"#versus\">A vCISO against the alternatives<\/a><\/li>\n    <li><a href=\"#when\">When a vCISO makes sense<\/a><\/li>\n    <li><a href=\"#regulators\">Where regulators expect a named officer<\/a><\/li>\n    <li><a href=\"#osto\">How the Osto vCISO works<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"does\">What a vCISO does<\/h2>\n\n<p>Accountability, not implementation. A vCISO decides what matters and in what order, and answers for it when somebody asks.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Area<\/th><th>What it involves<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Security strategy and roadmap<\/td><td>What to fix first given your actual risk, your stage and your budget, sequenced rather than listed<\/td><\/tr>\n    <tr><td>Audit and board readiness<\/td><td>Preparing for <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> or a regulator, and presenting the position to a board or investor<\/td><\/tr>\n    <tr><td>Policy and control design<\/td><td>Choosing controls that fit how the company actually works, and writing the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">governance<\/a> around them<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident response<\/a> planning<\/td><td>Deciding who decides, who notifies, and running the exercise that proves the plan works<\/td><\/tr>\n    <tr><td>Risk decisions<\/td><td>Owning the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment<\/a> and being the person who accepts or rejects a risk in writing<\/td><\/tr>\n    <tr><td>Customer and buyer conversations<\/td><td>Fronting the technical review when a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">security questionnaire<\/a> escalates into a call with their security team<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">A vCISO is not an engineer<\/p>\n  <p>If what you need is somebody to configure <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">access controls<\/a>, tune alerts or patch systems, that is a security engineer and the two are not interchangeable. A vCISO is worth the money when the missing thing is a decision-maker, not a pair of hands. Hiring one to do implementation work is the most common way the engagement disappoints.<\/p>\n<\/div>\n\n<h2 id=\"versus\" class=\"c-sage\">A vCISO against the alternatives<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Option<\/th><th>What you get<\/th><th>Where it falls short<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>vCISO<\/strong><\/td><td>Senior judgement, accountability and continuity, part-time<\/td><td>Limited hours, so it works only when execution capacity exists elsewhere<\/td><\/tr>\n    <tr><td>Full-time CISO<\/td><td>Total ownership and availability<\/td><td>Cost that rarely makes sense below a certain scale, and a slow hire in a thin market<\/td><\/tr>\n    <tr><td>Security consultant<\/td><td>Deep expertise on a defined project<\/td><td>Leaves when the project ends, taking the context with them<\/td><\/tr>\n    <tr><td>Security engineer<\/td><td>Hands to build and operate controls<\/td><td>Not the person who owns risk decisions or speaks to a board<\/td><\/tr>\n    <tr><td>Compliance platform alone<\/td><td>Controls, evidence and monitoring<\/td><td>A platform cannot accept a risk, brief a board, or decide what to do next<\/td><\/tr>\n    <tr><td>Founder does it<\/td><td>Free, and viable for a while<\/td><td>Stops scaling the moment the first regulated customer or serious audit arrives<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"when\" class=\"c-sky\">When a vCISO makes sense<\/h2>\n\n<p>The requirement almost never appears gradually. It arrives with an event.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 172\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Trigger events that create the need for a vCISO: enterprise deal, funding round, regulation, audit and incident.\">\n  <rect x=\"10\" y=\"26\" width=\"140\" height=\"80\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"80\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#4a52a8\">Enterprise deal<\/text>\n  <text x=\"80\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Their security team<\/text>\n  <text x=\"80\" y=\"87\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">wants a counterpart<\/text>\n\n  <rect x=\"158\" y=\"26\" width=\"140\" height=\"80\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"228\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#4a52a8\">Funding round<\/text>\n  <text x=\"228\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Diligence asks who<\/text>\n  <text x=\"228\" y=\"87\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">owns security<\/text>\n\n  <rect x=\"306\" y=\"26\" width=\"148\" height=\"80\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"380\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#ffffff\">Regulation<\/text>\n  <text x=\"380\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#b9c1e6\">A named officer<\/text>\n  <text x=\"380\" y=\"87\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#b9c1e6\">becomes mandatory<\/text>\n\n  <rect x=\"462\" y=\"26\" width=\"140\" height=\"80\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"532\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#4a52a8\">First audit<\/text>\n  <text x=\"532\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Somebody has to<\/text>\n  <text x=\"532\" y=\"87\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">own the programme<\/text>\n\n  <rect x=\"610\" y=\"26\" width=\"140\" height=\"80\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"680\" y=\"54\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#3a6f5d\">An incident<\/text>\n  <text x=\"680\" y=\"74\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">The worst moment<\/text>\n  <text x=\"680\" y=\"87\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">to start looking<\/text>\n\n  <rect x=\"10\" y=\"118\" width=\"740\" height=\"42\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"144\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Four of these five give you notice. The fifth does not, which is the argument for arranging it early.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"regulators\" class=\"c-plum\">Where regulators expect a named officer<\/h2>\n\n<p>This is the part founders often discover late. Several frameworks and regulators do not merely recommend security leadership, they require an identifiable person.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Regime<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>RBI IT Governance Directions<\/td><td>A designated information security officer with a defined reporting line, for entities in the applicable NBFC layers<\/td><\/tr>\n    <tr><td>SEBI CSCRF<\/td><td>A designated officer responsible for cyber security, scaled to the entity&#8217;s category<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/td><td>Accountability for personal data, with contact details published for data principal grievances<\/td><\/tr>\n    <tr><td>CERT-In Directions<\/td><td>A designated point of contact for incident reporting<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a><\/td><td>No job title mandated, but roles and responsibilities must be assigned and evidenced<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a><\/td><td>Formally assigned responsibility for the information security programme under requirement 12<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>None of them say the person must be a full-time employee. What they consistently require is that a named individual can be pointed to, which is precisely what a vCISO arrangement provides.<\/p>\n\n<h2 id=\"osto\">How the Osto vCISO works<\/h2>\n\n<p>Security leadership on tap, without a full-time hire. The engagement covers security strategy and roadmap, audit and board readiness, policy and control design, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">incident response<\/a> planning.<\/p>\n\n<p>What makes it different from a standalone consultant is that the platform sits underneath. Controls run in Osto rather than across a dozen vendors, so the vCISO is reading live state instead of asking for a status update, and evidence for <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> and Indian sectoral frameworks assembles from one control set. That removes most of the status-chasing that normally consumes a fractional engagement, and leaves the hours for the decisions you are actually paying for.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Security leadership on tap<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Strategy, audit readiness, policy design and incident planning, sitting on top of a platform that already runs the controls. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Strategy and roadmap &middot; Audit and board readiness &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is a vCISO?<\/summary>\n  <p>A virtual chief information security officer: an experienced security leader engaged part-time to own strategy, policy, audit readiness and incident planning. The responsibilities match a CISO role. The engagement is fractional rather than a salaried hire.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between a vCISO and a CISO?<\/summary>\n  <p>The scope of the work is the same. The difference is employment model and availability. A vCISO works across a defined number of hours and usually serves several companies, so it suits organisations that need the judgement without the volume of work to justify a full-time role.<\/p>\n<\/details>\n\n<details>\n  <summary>When should a company hire a vCISO?<\/summary>\n  <p>Typically when an enterprise deal stalls on security review, a funding round raises diligence questions, a regulator requires a named officer, or a first audit is approaching. Arranging it before an incident is preferable, because an incident gives no notice.<\/p>\n<\/details>\n\n<details>\n  <summary>Does a vCISO satisfy a regulatory requirement for a named officer?<\/summary>\n  <p>Usually yes, provided the individual is genuinely identifiable, has defined responsibilities and a documented reporting line. Regulators generally require a named accountable person rather than a full-time employee. Confirm the specific wording that applies to your entity type.<\/p>\n<\/details>\n\n<details>\n  <summary>Can a vCISO replace a compliance platform?<\/summary>\n  <p>No, and neither replaces the other. A platform runs controls and produces evidence. A vCISO decides which controls matter, accepts risk, and speaks for the programme. Buying one without the other leaves either decisions with no execution or execution with no direction.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">Security Questionnaire<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A vCISO gives you security leadership without a full-time hire: someone accountable for the strategy, the board conversation and the\u2026<\/p>\n","protected":false},"author":8,"featured_media":1146,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[546,548,547],"class_list":["post-1145","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-vciso","tag-vciso-vs-ciso","tag-virtual-ciso"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1145","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1145"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1145\/revisions"}],"predecessor-version":[{"id":1147,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1145\/revisions\/1147"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1146"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}