Skip Links

Network World

  • Social Web 
  • Email 
  • Close

How to fashion a 'security first' enterprise

When security pros think business, the business thinks security
By Cara Garretson , Network World , 03/17/2008
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

 

These forward-thinking IT managers are working at dismantling the stereotype of the risk-averse security professional-cum-business foe. How? By showing business colleagues they understand company operations and appreciate corporate goals.

"If security professionals' sole objective was to eliminate risk entirely, no one would have a BlackBerry, no one would have a laptop, and we'd all shred everything the second we read it," says Chad Mead, head of infrastructure security for Global Technology Infrastructure at JPMorgan Chase, headquartered in New York. "But today's business has changed and become much more mobile, so security has to become more of a partner with business."

Chad Mead, head of infrastructure security, Global technology Infrastructure, JPMorgan Chase

The need for security pros to tune in to business is not unlike the situation IT experienced about a decade ago, when organizations started thinking about technology as a strategic asset. Then, IT directors learned that presenting technology plans to the board or operational units without emphasizing business benefits was an exercise in futility.

"Businesses have to understand and be willing to listen to security people, but it's up to security managers to coax the business folks along," Mead says. "It's up to security professionals to change perception of security as impediment, and help business managers think of incorporating security upfront."


Quiz yourself on your security mindset

 


Security professionals who have operations backgrounds might find changing their mind-sets and becoming a partner to business easier than most. But an operations background is not essential. More important is that security managers get out of their offices and ask questions.

Prime objective

Understanding the business "should be the key objective for any risk manager," says Andre Gold, head of security and risk management for ING Financial Services in Hartford, Conn., and former CISO at Continental Airlines. At ING, as at Continental, Gold says he spent time learning how business operations such as call, distribution and maintenance centers work and measure success. "Once you understand the business, it gives you credibility. You can have conversations about security as a business enabler, not an inhibitor," he says.

Big results can come from small changes. At Akamai Technologies, Andy Ellis, senior director of information security, looks for opportunities to help business workers take small steps toward security.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Partner Content

Explore the Ultrium Edge

The powerful tape technology can address data security with tape encryption as well as long term data protection.

Find Out More

Disk and Tape Square Off

Discover what disk and tape really cost and which solution provides lower total cost of ownership and optimizes energy use for your organization

Download this White Paper

Don't Fall for the Myths

The Clipper Group explores the truth behind the myths of tape, digging into the misconceptions in the disk vs. tape debate.

Review this information

information examination

An examination of information security issues, methods and securing data with LTO-4 tape drive encryption

Read this analysis

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed