The InformationWeek -- Blogs

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

CISO: More Strategic Thought Needed


Posted by George Hulme, Apr 14, 2008 10:52 PM

The time has come for chief information security officers to become less tactical, more strategic.


Tim Wilson, site editor at our sister site, Dark Reading, covered some comments from former CA CIO Dave Hansen. Hansen now heads CA's Security Management business unit.

This part of the story struck a cord with me:

For their part, security pros need to do a better job separating operational issues from strategic business issues, Hansen said. "You are serving as a security strategist in the organization. Don't allow yourself to be consumed by the day-to-day tactical demands of the job. Build a strong team so that you can deliver value to the C-suite. Build a security framework that matches the goals of the business."

Security people need to build their visibility within the organization, but not solely as the "cops" who say no to everything, Hansen said. Security teams should look for ways to enable the business to do more, rather than just disallowing activities that might pose a risk.

Security managers do need the ability to pull the plug on initiatives that will pose greater business risk than business value. But they need to clearly articulate why certain initiatives may pose more risk than they're worth -- such as applications that somehow soared through development without a single security check until two weeks before the go-live date.

They'll be more valued when they can master the art of helping to devise innovative systems and initiatives that meet business objectives but also can be deployed securely.

InformationWeek VP and editor in chief Rob Preston said it well in this column:

The sooner security pros can converse in the language of risk mitigation and business opportunity, the more they'll be involved in strategic planning and the less they'll be considered a cost center.

« E-Ignorance Can Be Bliss | Main | Another CDP Vendor Bites The Dust. IBM Buys FilesX »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. HPC Joins the Dummy Revolution?
  2. Detecting Scalability Problems With Intel Parallel Universe Portal
  3. Just Say No To SFAQL Parallelism


Join The InformationWeek Group On LinkedIn


                           


  1. Top Resources To Save Big On Cyber Monday
  2. Google Branded Phone Rumored in 2010
  3. Murdoch And Microsoft Redefine Search
  4. LG Intros eXpo WinMo Smartphone With Pico Projector
  5. Sprint Targets Cyber Monday Instead Of Black Friday


  1. Microsoft Says Patch Isn't Cause Of Black Screen
  2. SAP Delays Support Price Increase
  3. Cisco Again Extends Tandberg Acquisition Deadline
  4. Ansca Mobile Releases Corona For iPhone Development
  5. HP Unveils 'Elite' Business Desktop
  6. Google Names Android App Winners

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007