* For security managers, people skills are as important as tech skills
endif; ?>Security has always been at the forefront of IT – indeed, the modern computer itself owes much to the legendary codebreakers and codemakers of the twentieth century. Security continues to make a substantial contribution to computing technology. Yet, with all our focus on technology, we sometimes forget that security is fundamentally a human problem. We are, after all, talking about the behavior of people, and the risks and threats their activities pose.
Few are more aware of this fact than the IT security manager. An IT professional is often attracted to security by the lure of cutting-edge technology. What they soon discover, however, is that their people skills must be at least as good as their technology skills – if not better.
The foundation of effective security management is a consistent security policy. This requires the development of a consensus on what that policy should be – a consensus which often must involve the co-operation of a number of individuals and groups, each with their own interests. As a result, the security manager must be something of a skilled politician. One stakeholder of a policy point may believe the security manager is lax if that point is not enforced. Others, however, may believe the matter to be a non-issue – or worse, that to enforce such a point actually runs counter to the interests of the business. Businesses that deal in the commodity of personal information, for example, feel this conflict keenly.
When consensus can be reached on what security priorities should be, the security manager often finds herself in a quintessential matrix management situation – requiring the cooperation of others to implement what they are expected to deliver. Network security measures must often be implemented by the network operations center staff, for example, while systems security measures are typically the responsibility of systems administrators – yet it is the security manager who will face the music if a breach occurs.
Once implementations are agreed upon, security remains a moving target. Not only are threats themselves constantly evolving – people do, too. Consider the challenge of role-based identity management. It’s easy to define roles once the organization knows what its business processes are – but how many businesses know what their processes are? And how adaptable are the tools for enforcing these processes as the organization and its people grow and change?
In order to build consensus and deliver the security the enterprise needs, the security manager needs tools that can help her communicate the reality of the security posture. When it comes to enforcement, she must be able to win the confidence of her peers who must help in the operation and maintenance of effective countermeasures.
This means metrics that effectively make the case, and enforcement tools that map the real world to how people actually work, able to adapt to practical changes without imposing artificial restraints.
As we at Enterprise Management Associates shape up our research calendar for 2006, I would very much like to hear from you as we investigate IT security solutions that really work – as well as those that don’t. What succeeds for you, and what are the gaps where tools are still missing the mark? Let me know about the solutions you feel are really meeting these requirements of real-world security management – as well as those you’re still waiting to see. Your experience may have more influence than you think!




