It's more about reducing risk in everyday practices than fighting threats.
endif; ?>Second in a four-part series on the toughest security issues affecting the enterprise.Read part 1 here.
Enterprise security executives need to make practices such as safe USB use and discreet handling of patient or customer data as commonplace as not accepting luggage from strangers in airports or wearing a seat belt when driving.
But they can’t do it alone; it takes an entire organization to secure corporate assets, protect data from breaches and make sure enterprisewide risk remains low.
“Security is everyone’s responsibility,” says John Kirkwood, vice president of Information Security Strategy at American Express, who spoke recently at a Boston seminar hosted by risk-management company Consul. Kirkwood, formerly chief information security officer at the financial services giant, says his role has evolved from security policy maker to enterprise risk-management evangelist. “Security has gone from being a server room concern to a boardroom type of issue,” he says.
Part of the reason companies need to reprogram IT organizations, business managers and employees to approach security as a way of life is that so many breaches are the result of insider mistakes. According to the 2005 Computer Security Institute/FBI survey, the number of security events originating within an organization is equal to those propagated by external sources. Privileged users, who have more access than typical users, perpetrate 43.5% of those inside security events.
“Security has evolved beyond a centralized team, and it has evolved beyond networks, systems, applications and databases,” says Paul Stamp, a senior analyst at Forrester Research. “Security can no longer exist in its stand-alone, enforcer function. It must exist as part of what everyone does, and it has to be created using a two-way flow of information between policy makers and business users.”
Such issues will be topics of discussion at next month’s inaugural Security Standard event in Boston.
| ||||||||||||
Business unit unity
To establish a security culture within a company, a logical first step is for security managers to work with other IT departments, as well as business managers from human resources and legal, and then spread the word through awareness and training programs to the entire corporate population. The responsibility for security moves from a technical, protection role to one that could be seen as enabling the business to function more efficiently and with less worry, industry watchers say.
“Many business units can be hesitant to bring in security, because in the past it has required them to do more work for additional costs and really impeded how they operated,” says Khalid Kark, a senior analyst with Forrester Research. “Security advocates have to educate the organization to incorporate security from the beginning of every project that comes along, because it is much more costly to retrofit.”
Kark says security policymakers must build or adapt security practices around how business units actually use systems and applications, rather than forcing a process or policy onto them.
“If you don’t talk to application users, you are going to build policies that will be broken right out of the box,” says Cory Elliot, IT director at Basic Energy Services in Midland, Texas. Elliot is working with the chief financial officer of the oil and gas well services company to assess the entire company structure, establish a security framework and fill gaps in security policies. He says he realized early that without upper management support and user buy-in the security practice project would be dead in the water.
“It’s not going to matter what kind of policy I build if I can’t educate the users – in layman’s terms – about what it means to them and why they should do it,” Elliot says. “If I can explain how them shutting down every night or using certain log-in processes helps the business and how it’s not just about making their jobs more difficult, I can make policies part of the way they do things.”
Such thinking is critical to success, says Brad Johnson, vice president of consulting at SystemExperts, a consultancy specializing in network security. He says there are elements of people’s jobs that can change to support security measures and others that cannot, depending on the organization, and security policy makers need to find the balance between best practices and pragmatic workflows.
“Successful security measures originate as a business concept from the top that permeates down into how people can change the way they work to better enhance data privacy and resource protection,” Johnson says. “It can’t be about the security manager acting as police officer, but rather as an advocate for a consistent security posture across departments, which could be argued enables faster application deployment time and streamlined operations.”
And don’t underestimate human nature when communicating the importance of keeping in line with security policies. Security managers can cite embarrassing public incidents to reinforce why a corporate population needs to fall in line.
Privacy Rights Clearinghouse reports that more than 53 million Americans’ personal information has been compromised since February 2005, and Forrester reports, “Most of these breaches occurred at companies that are household names, such as Bank of America, Time Warner and Ford.” According to the National Fraud survey, internal security attacks cost U.S. businesses an average of 6% of their gross annual revenue.
“No one typical user, omitting those that take part in malicious activities, wants to be the person that compromised patient data and put the organization in jeopardy,” says Ron Uno, manager of information management (and essentially acting CIO) at Kuakini Health Systems in Honolulu.
Uno meets every two months with other business unit leaders to reinforce and maintain awareness of established or updated security practices. He says recent public events – such as employees bringing a disk or laptop loaded with critical data home – keep the importance of security best practices fresh in managers’ minds. In the face of intentional breaches, Uno says action should be swift and definitive – yet also discreet to avoid public perception problems – to reiterate to the corporate community not to trifle with the established security culture.
Inside The Security Standard A preview of key sessions at this new event, taking place in Boston on Sept. 6 and 7. | ||||
|
“Security policies need to have teeth, and those who break the policies need to know and endure the consequences,” Uno says. “If you educate the entire employee base about the risks, the punishment and how the company could suffer, then as a security leader you have an army of people keeping their eyes and ears open and watching out that security policies are followed.”
While regulatory compliance and very public breaches may have spurred many organizations’ push to establish and enforce consistent security practices, it cannot remain the primary driver for an advanced security culture. For Kirkwood, his three-to-five year strategic plan for enterprise risk management at American Express includes tactical milestones to keep business units motivated within the security mind-set.
You can’t put security measures in place only because regulations require them, he says: “You have to have an enterprise risk management culture that security best practices and other IT and business initiatives feed into organically.”




