Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Security jobs are political - why would you want one?

Delving into the job of a chief information security officer
IT Careers and Training Alert By Linda Leung , Network World , 06/06/2007
Sign up for this newsletter now!

Senior Writer Jon Brodkin discusses IT career and education trends and issues.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Who would want to be a chief security officer? OK, you’d get a high salary – particularly if you are CISSP-certified, as many salary surveys show – and you’d get the satisfaction of creating a more security-savvy organization, but you’d probably be flitting from one company to another every three years. CSO often need to make changes in an organization that may not go down well with their colleagues, creating political tension and making it unpleasant for the exec to remain at the company.

That and many other issues delving into the job of a CSO were discussed at a CSO Bootcamp being held at Interop last month, which my colleague Senior Editor Tim Greene attended. In his story “CSOs lasting longer, but still out after three years”, Tim writes that attendees to the bootcamp now often have business backgrounds, a contrast from the first generation of CSOs made up of ex-techies, who were tasked at putting out the immediate fire.

John Pironti, the chief information risk strategist for Getronics who ran the bootcamp, said that part of the politics stems from the need to influence all people in IT to make security a priority. Also, there’s the need to foster a culture of security across the whole organization. Hiring outside consultants to audit a company’s security and making recommendations could help alleviate the need for the CSO to be critical of the organization, said Pironti.

Tim’s story includes a full report from the boot camp, as well as a side bar on CSO tactics to influence secure network behavior.

Another story of interest is Cara Garretson’s “What it takes to be a great CISO”, reporting on a speech given by Eddie Zeitler, executive director of (ISC)2, which manages the CISSP and other security certifications. Speaking at (ISC)2’s 2007 SecureAmericas conference late last month, Zeitler said the function of information security is splitting into two, with security technology moving back to the IT department and administration of security becoming a management issue, reports Cara.

Management skills now trump technology skills for an effective CISO, said Zeitler, as accountability for IT security has shifted out of the IT department and up the corporate ladder to the CISO and even the CEO.

Technical competence is valued in CISOs, but soft skills is high up on the list of must-haves for security professionals, according to Zeitler.

Jon Brodkin is senior writer at Network World.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Partner Content

Blue Stripe Software

www.bluestripe.com/

Improving Application Performance Troubleshooting

Diagnosing why an application is slow is hard, at times taking days or weeks to isolate and resolve. This paper explains the challenges involved using current management tools, provides a 'wish list' for application management and analysis, and explains the need for an application system-wide approach that monitors entire applications, not components.

Download Whitepaper

Virtual Vigilance: Managing Application Performance in Virtual Environments

This paper highlights the impact of virtualization on application performance.  "Managing Application Performance in Virtual Environments" states: "Best-in-Class organizations are predominately taking actions around improving visibility across both physical and virtual systems, assessing the business impact of application performance and understanding interdependencies of applications in virtualized environments."

Download Whitepaper

Application Service Requests: The Missing Link for Pragmatic ITSM

Forrester Research analyst Glenn O'Donnell and BlueStripe co-founder Vic Nyman discuss a breakthrough approach to application problem management. Learn the new approach for ITSM problem management, which provides: Rapid isolation of application slow-downs to specific components for quick problem resolution, 24/7 monitoring for proactive notification of potential issues before end users are impacted and much more.

Register for Webcast

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed