- Bank Web sites full of security holes
- SCO Group: Its future is all used up
- Maligned feature being added to IPv6
- I returned my iPhone 3G after six days!
- VPNs: Six burning questions
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
In this series of columns, I’m reviewing and commenting on ideas in A Seat at the Table for CEOs and CSOs: Driving Profits, Corporate Performance & Business Agility by Jackie Bassett and Daniel Rothman and edited by Raquel Filipek.
The authors’ Chapter 1 is entitled “Why?” They start with five key reasons for CEOs to include CISOs in what I would call strategic planning (thinking about long-term, mission-critical goals and global processes). Each reason has explanations from the authors, but it’s worth simply listing them to give readers a sense of the issues (quoting directly):
1. Because to every CEO there are no competing business priorities to revenues and profitability.
2. Because in today’s global economy, it’s innovate or perish.
3. Because it makes good business sense.
4. Because CEOs have arrived at the same near-paralyzing epiphany. [i.e., the realization that “…companies simply can’t continue
operating under the same business security model.”]
5. Because “insanity is doing the same thing over and over, and expecting a different result.” – Albert Einstein
Bassett and Rothman propose that “Security today has become a reverse salient – a growth inhibitor or a system component that has fallen behind in the evolutionary process of technological innovation.” They argue that it’s time to bring security into the forefront of strategic planning. They point out that in a 2006 study of “100 of the most innovative companies,” “more than 95% of CSOs [chief security officers] or CIOs [chief information officers] report directly to the CEO or to a senior vice president who reports directly to the CEO and plays a significant role in strategic planning.”
On a personal note, I and many other security management specialists have long argued that the CISO must not report to the CIO any more than the head of financial audit should report to the CFO. CISOs and auditors should not have a conflict of interest by reporting to the people whose management they ultimately evaluate on behalf of all the stakeholders in the organization.
Bassett and Rothman’s key points about the optimal strategic orientation of CISOs and CEOs include the following practical suggestions (these are my own interpretations of just a few of their insights - readers would do well to read the original):
If the IT manager is knowledgeable regarding Cisco technology, he would have 2 options. Option 1 - Consult...- Anonymous
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment