How to fashion a 'security first' enterprise
- 19 March, 2008 10:29
- Comments
These forward-thinking IT managers are working at dismantling the stereotype of the risk-averse security professional-cum-business foe. How? By showing business colleagues they understand company operations and appreciate corporate goals.
"If security professionals' sole objective was to eliminate risk entirely, no one would have a BlackBerry, no one would have a laptop, and we'd all shred everything the second we read it," says Chad Mead, head of infrastructure security for Global Technology Infrastructure at JPMorgan Chase, headquartered in the US. "But today's business has changed and become much more mobile, so security has to become more of a partner with business."
The need for security pros to tune in to business is not unlike the situation IT experienced about a decade ago, when organizations started thinking about technology as a strategic asset. Then, IT directors learned that presenting technology plans to the board or operational units without emphasizing business benefits was an exercise in futility.
"Businesses have to understand and be willing to listen to security people, but it's up to security managers to coax the business folks along," Mead says. "It's up to security professionals to change perception of security as impediment, and help business managers think of incorporating security upfront."
Security professionals who have operations backgrounds might find changing their mind-sets and becoming a partner to business easier than most. But an operations background is not essential. More important is that security managers get out of their offices and ask questions.
Prime objective
Understanding the business "should be the key objective for any risk manager," says Andre Gold, head of security and risk management for ING Financial Services, and former CISO at Continental Airlines. At ING, as at Continental, Gold says he spent time learning how business operations such as call, distribution and maintenance centers work and measure success. "Once you understand the business, it gives you credibility. You can have conversations about security as a business enabler, not an inhibitor," he says.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Webcast: The Application Reality
- Demonstrating Return on Investment with Enterprise-Class Identity and Access Management Technology
- Case Study: NZ Bus Develops Applications 60% Faster, Improves Database Performance by up to 35%
- Securing and Managing Your Enterprise: An Integrated Approach
- Forrester Research | Your Enterprise Database Security Strategy 2010
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Nokia N9: Why you shouldn't buy this device
-
Microsoft at a loss over Event Viewer scam
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 for Dummies
-
Teach Yourself Visually Windows 7
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies®
-
Windows 7 for Seniors for Dummies®
-
Computers for Seniors for Dummies, 2nd Edition
-
MYOB Software for Dummies 6E Australian Edition












Comments
Post new comment