* Why policy management is becoming more critical
It’s not easy being an information security officer. Technologists often approach the position believing it’s an exciting opportunity to interact with a wide range of innovative technology – which it is. What they soon discover, however, is that the role requires as much – if not more – in the way of people skills.
Take the ChoicePoint case, for example. The company’s business is making valuable personal information available in a controlled way. From everything I have read about their case so far, it seems its security people did the job they were hired to do.
The real issue was one shared by many other businesses that otherwise have little if anything in common with ChoicePoint. On the one hand, enterprise firms seek to manage risks as much as possible. This implies well-defined controls on information assets. At the same time, businesses are highly motivated to extend information – often sensitive information – to their customers and partners as much as they can. How can these requirements be balanced?
It’s people, not technology, that define policies governing what’s important to protect and how – as the compliance-sensitive business knows only too well. One of the most important jobs of the chief information security officer is to help guide the business toward agreement on policy, balancing requirements like these. Once articulated, policy must then be put into operation – but with an estimated 2,000 or more vendors in the security and compliance marketplace, how can policy be implemented consistently across the enterprise?
These are the reasons why policy management is a becoming vital discipline. It provides the tools necessary to bring a range of segmented controls together into a comprehensive architecture.
Expect to see much more of this trend:
– At the top level, in management products that can enforce policies across a range of point products. In the security camp, examples include security information management systems, which increasingly have a policy or compliance management flavor. In operations, tools such as configuration and change management, software management and network flow management are each playing a larger role in a comprehensive approach to policy management.
– In infrastructure, in products that can interpret and enforce policy at key control points. Examples over the past year include various approaches to endpoint security, which are evolving to become more comprehensive in what they can monitor and enforce. As visibility into the security of data itself increases, vendors will increasingly tackle how to control specific types of data passing through a network. Today’s high-performance protections for composite applications such as application firewalls are one example of where the technological demand is already high – and will become higher as control points and enforcement opportunities for service-oriented architectures become clearer.
At issue is the question of trust – a fundamentally human thing, and the most difficult policy issue of all. There will always be a horizon beyond which some level of trust has to be assumed, yet there is much that can be done to monitor and enforce trustworthy behavior, such as dividing responsibilities and assuring that sensitive actions don’t take place in isolation. This is fertile territory for development, which is expected to be active. Watch this space for updates.




