Computerworld

What would you do as chief information security officer

Four CSOs share insights into what's involved in being the security guardians of their enterprises

Becoming the chief information security officer (CISO) of a corporation makes you a strategic IT advisor to business management, the chief information officer, and the rest of the information technology staff. Just as no company is the same as another, the job of CISO -- or alternately, "chief security officer," which might include physical security as well -- isn't either. The four security professionals who share their priorities with us make it clear there's nothing cookie-cutter about the top IT security job.


Name: Beth Cannon

Title: Chief security officer at San Francisco-based merchant bank Thomas Weisel Partners

Installed base: 700 employees using servers, desktop and laptop computers, plus 450 handhelds, mainly BlackBerry

Broad concerns about regulatory compliance were instrumental in creating the chief security officer job at merchant bank Thomas Weisel Partners back in 2004.

"Among the drivers for the CSO job were the disaster-recovery rules coming into play from the Securities and Exchange Commission (SEC) after 9/11," says Beth Cannon, the first-ever CSO there. "We also needed to look at Sarbanes-Oxley because we were planning to go public."

Thomas Weisel Partners decided to carve out the job in order to have a point person acting as central liaison between the legal department, IT and upper management in crafting IT security policy.

Cannon, who reports to the CIO, said she has made it a priority to have telecom providers disclose how lines to the bank's corporate clients are routed to avoid an over-concentration in one area -- one horrible lesson learned after the Sept. 11 terrorist act on New York -- and is looking at VoIP as an option for some services to users.

While it's not always easy to build unity internally around security policies, one advantage, she says, is that her eight-year tenure at the firm -- she was the chief technology officer there before accepting the position as CSO -- meant "I've built a lot of relationships."

This helped in the situation when she had to sit down with the legal department and IT to hammer out security policies she was advocating for the hundreds of BlackBerries and laptops that employees take with them for mobile computing.

While sometimes employees balk at policies such as password time-outs or encryption that may add complexity, says Cannon, it's easier to help change a pattern of computer behavior when the discussion occurs between people who personally know each other. "The relationship really becomes the key," said Cannon.

More about: ACT, American Express, BlackBerry, Dell, Deloitte & Touche, Dovetail Distribution, Ernst & Young, Ernst & Young, Guaranty Financial, HIS Limited, IBM, IPS, JP Morgan, McAfee, Morgan, NATO, NetIQ, Oak Ridge National Laboratory, PLUS, SEC, Securities and Exchange Commission, TippingPoint, TippingPoint, Wells Fargo

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Community Comments
Whitepapers
All whitepapers
 
Featured Whitepapers
Implementing Energy Efficient Data Centers

It is possible to dramatically reduce data centre electrical consumption through appropriate design of the network-critical physical infrastructure and through the design of the IT architecture. Find out how - read on.

Zones
SAS Resource Centre

This Resource Centre hosts a wealth of thought leadership articles, whitepapers, and success videos, to help you make the most out of your corporate information in order to swiftly make sound business decisions to survive and thrive in the current economic climate.

Oracle Resource Centre

News, Features and the latest whitepapers on SOA, Application Grid, Enterprise Management and Database

Computerworld newsletter
Join the most dedicated community for IT managers, leaders and professionals in Australia
Sponsored Links
 
Copyright 2010 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.