WASHINGTON, DC – An effective chief information security officer is a trusted advisor to the company, a respected leader of his or her technical team, and a risk expert all at once … which is no small task, according to a panel of CISOs who spoke at the Computer Security Institute’s conference held here this week.
During a keynote discussion entitled “CISO Panel: Evolving Responsibilities,” five CISOs from various industries and government offered opinions on what it takes to become a CISO, how to hold on to the title, and in which directions the job is heading.
The demand for a CISO function has jumped dramatically in the past few years, largely because of new security-related requirements imposed on public companies by the Sarbanes-Oxley Act (SOX), said Bill Hancock, vice president of global security solutions and chief security officer at IT services company Savvis Communications. Due to the criminal charges that SOX may impose on corporate officers who violate the law, one could say that the CISO’s job is to keep management out of jail, Hancock says.
Another panelist joked that while corporate security is a cost center and its value can’t be easily gauged, if ROI is defined not as ‘return on investment’ but ‘risk of incarceration,’ suddenly it seems worth funding. “Security is all about risk avoidance … I’ve found it impossible to quantify,” said Jennifer Bayuk, CISO and managing director with financial service firm Bear Stearns.
The panelists agreed it’s getting easier to sell the need for security to both company executives and to customers, as breaches have become headlines thanks to a California law http://www.networkworld.com/news/2003/0630california.html?brl that took effect this year forcing companies that do business in that state to disclose when an event occurs that could lead to theft of personal data.
While the need for security must be stressed, so should the reality that there’s no such thing as 100 % security, said Jack Jones, CISO of Nationwide Insurance. “If perfect security isn’t achievable, then we’re managing the frequency and magnitude of loss…we have to become experts at risk,” he said.
Experts at managing risk, not taking risks, Jones added, which is why the CISO position is not typically a path to the corner office. “CEOs have to have a high tolerance for risk, I find I’m risk averse,” he said.
Yet some CISOs are finding their experience with managing risk and understanding the company’s business means they are asked for help by many different departments. “The CISO is becoming a trusted advisor to all parts of the company,” said Hancock, adding that much of what he does these days falls well outside the scope of his duties.
Meanwhile, a CISO needs to keep up to date with technology in order to effectively manage their staff. They must be “technical enough so you’re not snowed, but have enough management [skills] that you can fit in and talk to business folks,” said Jane Scott Norris, CISO with the U.S. Department of State – the first person to hold such a title within that agency.
Another key skill for CISOs is to understand auditing and use it to their favor. “If you can’t demonstrate that you’re secure, it doesn’t count,” Bayuk said.




