CISO Network

Community Standards

Code of Conduct

Effective date: January 1, 2025

The CISO Network has been the most trusted peer community for cybersecurity leaders since 2005. Our reputation is built on mutual respect, professional integrity, and the confidentiality of our members. Every member is expected to uphold these standards without exception.

Core Principles

Integrity

Be honest, transparent, and act with the highest professional standards in all interactions.

Respect

Treat every member with dignity regardless of title, company, background, or viewpoint.

Confidentiality

Protect sensitive information shared within the community. What is shared here, stays here.

Professionalism

Maintain the standards expected of senior security leaders in every post, message, and interaction.

1. Professional Conduct

All members are expected to engage in a manner consistent with senior professional standards. This includes:

  • Communicating respectfully and constructively, even when disagreeing;
  • Providing accurate and honest information in all discussions;
  • Acknowledging the expertise and contributions of fellow members;
  • Refraining from personal attacks, insults, or disparaging remarks about individuals or organizations;
  • Disclosing relevant conflicts of interest when participating in discussions about vendors, products, or services.

2. Confidentiality & the Chatham House Rule

The CISO Network operates under the Chatham House Rule: members may freely use information received in community discussions, but may not reveal the identity or affiliation of the source.

Specifically, you agree to:

  • Not share, quote, screenshot, or republish content from private forums, groups, or direct messages outside the platform without the explicit consent of the author;
  • Not attribute statements made within the community to specific individuals or organizations in external communications;
  • Treat incident details, vulnerability disclosures, and security program information shared by members as strictly confidential;
  • Not use information obtained through the platform to gain competitive advantage or to harm any member or their organization.

3. Prohibited Content & Behavior

Strictly Prohibited

  • Harassment, bullying, or intimidation of any member in any form
  • Discrimination based on race, ethnicity, gender, religion, sexual orientation, disability, age, or any other protected characteristic
  • Sharing malware, exploits, or attack tools without explicit educational context and appropriate warnings
  • Soliciting members for commercial purposes without prior written approval from CISO Network administration
  • Posting false, misleading, or defamatory information about individuals, companies, or products
  • Sharing another member's personal contact information without their consent
  • Impersonating another member, professional, or organization
  • Engaging in or facilitating any illegal activity
  • Posting content that violates any third-party intellectual property rights

4. Vendor & Commercial Activity

The CISO Network is a peer community, not a sales channel. Commercial activity is strictly regulated:

  • Unsolicited vendor pitches, product promotions, or sales outreach to members are prohibited;
  • Members who are also vendors must clearly disclose their commercial affiliation when discussing their own products or services;
  • Sponsored content and vendor participation are permitted only through official CISO Network sponsorship programs;
  • Job postings must be submitted through the official Job Board feature.

5. Security Research & Vulnerability Disclosure

Given the nature of our community, discussions of security vulnerabilities, exploits, and attack techniques are common. Members must:

  • Follow responsible disclosure practices when discussing known vulnerabilities;
  • Not share zero-day exploits, active attack tools, or information that could enable harm to systems or individuals;
  • Clearly label theoretical or educational content as such;
  • Comply with all applicable laws regarding computer security research, including the Computer Fraud and Abuse Act (CFAA) and equivalent laws in other jurisdictions.

6. Reporting Violations

If you witness conduct that violates this Code of Conduct, please report it immediately using the Report Behavior feature in the Member Support section, or by emailing [email protected].

All reports are treated confidentially. Retaliation against members who report violations in good faith is itself a violation of this Code of Conduct and grounds for immediate removal.

7. Enforcement

Violations of this Code of Conduct may result in:

  • A formal warning;
  • Temporary suspension of posting privileges;
  • Permanent removal from the CISO Network;
  • Referral to appropriate legal authorities where conduct may be unlawful.

CISO Network administrators have sole discretion in determining appropriate enforcement actions. Decisions are final.

8. Acknowledgment

By registering for and using the CISO Network member platform, you acknowledge that you have read, understood, and agree to abide by this Code of Conduct. Failure to comply may result in immediate removal from the community without refund.

Questions about this Code of Conduct should be directed to [email protected].

See something? Say something.

Report conduct violations confidentially through the Command Center.

Report a Violation