TechNet, a national organization of technology industry CEOs pushing a policy agenda, tackles four to six issues per year, and this year one of the main agenda items was cybersecurity. The TechNet task force that was assigned the job developed a security self-evaluation tool for business leaders that will be announced Dec. 3 at the Department of Homeland Security’s National Cyber Security Summit in Santa Clara. Arthur Coviello, president and CEO of RSA Security, co-chair of TechNet New England and a cybersecurity task force member, described the tool and the task force’s goals to Network World Editor in Chief John Dix.
Before we get to the security tool, give us a little background on the mission of the cybersecurity task force.
Basically to provide a mechanism for TechNet members, one, to inform and influence cybersecurity policy making and commercial sector practices; two, to support public/private efforts to protect America’s information infrastructure; and three, to promote awareness and best practices in cybersecurity – which is what this tool is about – then develop policy statements on key topics. What we’re trying to do is get everyone to use this self-assessment tool by April 4, 2004, which would be roughly four months after we announce it. We’re calling it a national cybersecurity day.
Describe the tool.
It covers multiple areas. One section is on business dependency, how much you rely on IT. Then there is a section about risk evaluation and then a segment about people, evaluating the personnel aspect of your information security program. Then processes: What are your processes for implementing security? And technology evaluation is the last section.
Is it aimed at CEOs?
The CEO and CIO ought to look at the business-dependency and risk-management evaluation, and then bring in other people for the people, process and technology sections. It is a questionnaire. It is not a panacea for security. But if you follow these questions it will lead you down the path of how to properly evaluate your security and help you recognize where you might be deficient.
The primary purpose of us doing this is we don’t think there is enough awareness about cybersecurity at the CEO level. Now, I happen to think that the planets are aligning and there is certainly far more CEO attention being called to issues of internal control – especially with Sarbanes-Oxley’s provisions on internal control – and any cybersecurity system tends to be a subset of your overall internal control system.
So this tool gives CEOs the ability to look at the cyber aspects of their overall system of internal controls and make sure that particular flank is covered. And as more companies rely and depend on the Internet to run their businesses, this tool becomes more critical to use and understand.
You said you used the tool internally at RSA and it actually helped. What did you discover?
It allowed me to revisit a lot of the work we had done and do it in a very structured fashion. And keep in mind that any cybersecurity system, or any system of internal control, needs to be constantly reviewed and updated. And this gives a very useful guideline not only for evaluating it for the first time, but also for going back on a regular basis to ensure that things are properly updated and followed.
Our documentation around policy and procedures needed to be better, because with changing personnel you have to make sure these things are documented. I certainly found it useful in that respect. I also found it useful in terms of confirming the things we were doing correctly, that we had the processes and technology and the people watching over it.
How long does the evaluation take?
It can be done in a matter of hours, but a lot of it is in the follow-up work, in following up questions that you might not have the answers to. It will vary from business to business.
There could be wide divergence in the time it took us vs. a company that needs to overhaul its internal controls. But in terms of just pointing you in the right direction, just to get through the questionnaire itself is a matter of hours. It’s about 80 questions, 15 pages. (The document will be available at www.technet.org after Dec. 3.)
How many people do you need to assemble to get through it?
You’re going to want to start off with the CEO, the CIO, the CSO if you have one, certain members of the IT team. I would recommend you bring the CFO into the discussion as well. Depending on what issues come out of it, then you’re going to bring in other staff to see that issues that need to get addressed get addressed by the appropriate functional area.
Why should CEOs believe a bunch of security vendors about the best approach to security? Won’t most be suspect of your motives?
We reference a lot of material, and we’re not telling people to go out and buy all sorts of products. But if companies such as RSA and Internet Security Systems and VeriSign don’t know at least about the technology, I don’t know who the heck would. Certainly other folks like the CPA firms can add a lot of value, but this is a tool that is pretty generic, and I would think people would give us a certain amount of credit for having the right knowledge and expertise to make a judgment in this area.
Is your hope that if industry does these self-evaluations it will preempt any efforts to regulate security?
What we want from the government is to play the right role. There seems to be violent agreement that it would be very difficult for federal and state government to legislate specific technologies around security because, one, the lack of expertise, whether it is the FCC or Congress or in general; and two, the dynamic nature of IT systems.
Having said that, the government already regulates a number of industries, such as public utilities, telecommunications, financial services and healthcare. And I’m certainly not suggesting that government doesn’t have a role to play in respect to issues of individual consumers and people’s privacy. But to legislate very specific requirements around cybersecurity where industries and risk profiles are so different, I would not be in favor of seeing that.
We need companies to self-regulate. There is a strong market requirement to do that – risk of financial loss, risk of loss of reputation, trust. And there are technologies out there that can take care of the lion’s share of the threats, and that’s why TechNet’s leadership is good in terms of promoting that.
If you look at any of the spending and budget polls, you’ll always see security at or near the top, so companies are taking the issues seriously. We would like to see CEOs have a better understanding overall of why the issue is so important. And it comes back to the tool as being a good way to bring awareness at the CEO level.
You talk about security being a business-level concern now. How best can IT leaders promote this within their organizations?
There is a tendency for technologists just to think in terms of technology and talk about budgets for this and implementing that, and because we understand as technologists the business importance for it, we assume others do.
This tool, especially the business-dependency and risk-assessment aspects, should be something that is read by technologists so that when they communicate with upper management they can put issues in context. In that sense it is a great tool.




