sͧb̴ͫƸ̴gͬᵉ<p>I* have invented** an <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> visualisation for any <a href="https://infosec.exchange/tags/CISO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CISO</span></a> to use while workshopping on Post-Its with management - the "subm3rge surface"*** metric.</p><p>All too often when prioritising what's on the Post-Its, be it <a href="https://infosec.exchange/tags/BCP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BCP</span></a>, <a href="https://infosec.exchange/tags/DR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DR</span></a>, or just plain operations steps, (senior) managers will want to hedge, like "It depends on situation" or "There's some priority overlap between these two areas". This makes the whiteboard exercise messy, and designing efficient <a href="https://infosec.exchange/tags/ISMS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ISMS</span></a> or <a href="https://infosec.exchange/tags/risk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>risk</span></a> <a href="https://infosec.exchange/tags/governance" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>governance</span></a> harder, since it creates dependencies and coordination costs that are hard to <a href="https://infosec.exchange/tags/visualise" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>visualise</span></a> in the <a href="https://infosec.exchange/tags/workshop" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>workshop</span></a>.</p><p>The "subm3rge surface" metric helps you visualise the increased costs to management, in one simple step: When placing the Post-Its on the whiteboard, mind your priority overlap vertical. And when presenting the total cost factor of <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> work, present the *outer envelope* size of all dependent Post-Its. It's that simple.</p><p>In a "clean" vertical of priority, it's cheap/easy, as we know. And even in the horrifying "flat" priority, it's at least cheap to implement... But the interlocked unclean priority ladder, that's the expensive one. </p><p>The "subm3rge surface" metric helps you show that! </p><p>*/**(yes this is a blatant attempt at getting some replyperson to show me the prior art :)<br>***(catchy, eh? :)</p>