There's a better tactic for getting budget approval
Great security always requires one thing: an adequate budget. Getting the funds, however, can be a hard sell. If all goes well with security, nothing happens – a difficult position to be in when trying to prove the value of the investment. Network executives often resorted to painting grim pictures of lost revenues from potential threats to get the dollars they needed for security projects. But members of the CISO inner circle say those days are gone.
“If you try successive waves of scaring executives to control budgets, then you increasingly get labeled as the boy who cried wolf, and that doesn’t do you any good,” says Michael Barrett, CISO of PayPal in San Jose, Calif. Instead, he models the financial services approach and applies risk-management techniques to all things security. Just as financial planners decide on how much money to budget to protect capital investments (liability insurance for buildings, for example), IT execs can decide how much money to invest to protect their IT investments. “As organizations get better at risk management, they begin to ask, what other risk classes do we have to worry about and how much is the right level of money to invest? Once you get a risk-management view of the world, the whole [budget] conversation is staggeringly easier to have,” Barrett says.
Another tactic is to avoid using the word “security” altogether. This approach is favored by Joseph Moorcones, vice president for worldwide information security at Johnson & Johnson in New Brunswick, N.J. “It’s too hard to sell ‘security.’ You have to sell how to help the company grow and manage its information assets just like it manages its financial assets. When you do that, security becomes an enabler,” he says. “This is about having good ‘information-asset protection’ policies. We try not to use the word ‘security.’ This is something that enables the business, not something that disables it by making it hard to do things.”
Another way to scare up the necessary budget is to dovetail projects planned with security audit results. Johnson & Johnson has a unique approach to the auditing process, Moorcones says. It has created a rating scale for security, modeled after the Carnegie Mellon Software Engineering Institute’s Capability Maturity Model for Software. It rates security capability of companies on a five-point scale for each major security area. It ultimately describes each security area as “acceptable or not acceptable,” he says. Moorcones’ team conducts such security audits annually for 20 to 25 of Johnson & Johnson’s subsidiaries using this system. The team also reports to each subsidiary “where it sits relative to its peers,” such as the top 20% or the bottom 20%, as well as its rating on the five-point scale. Also included are the team’s recommendations on how to improve low-rated areas. Results are shared with the corporate CIO and consequently can be used to help the unit get the financial resources it needs to improve security.
Ultimately, though, the largest budget in the world isn’t enough to make a company secure, Moorcones cautions: “Security is something you do, not buy.”
CISO inner circle >




