Computerworld
CSOs need to keep evolving, CA security exec says
CA executive urges CSOs at RSA Conference to strategize and make themselves heard
Network World staff (Network World)  14 April, 2008 08:18

This is a transcript of a keynote address presented at the RSA Conference on Thursday by Dave Hansen, corporate senior vice president and general manager for CA's Security Management Business Unit. The address is titled: "Strategic Security: The Evolving Role of the Security Professional."

Good afternoon.

Today, I am going to talk about security, but more specifically, I am going to explore the evolving role of the security professional.

In some organizations the senior security person is called the Chief Security Officer. Other companies use different titles -- Vice President, Enterprise Security; CISO (chief information security officer); VP Security & Compliance, and so on. To keep things simple today, I am going to talk about the CSO, but please understand that my focus is on the senior-most security professional, no matter what title that role carries in your organization.

As everyone here knows, the job is changing. Not in quiet, imperceptible ways, but in ways that are loud, visible and meaningful.

When the role of Chief Security Officer emerged as a defined position, the common perception was that the role was akin to a corporate cop -- on patrol within the organization to slap wrists when somebody broke the rules. Nobody really thought the cop was necessary, so, generally the position didn't get a great deal of respect.

But that's changed. In today's well-run enterprises, the CSO is more visible, has more authority -- and more responsibility. No longer merely an enforcer of security protocol, the CSO works with the CIO, CFO and other C-Suite executives as a business enabler, a strategist, and a security evangelist who helps the organization recognize the need to embed secure practices in every facet of the business.

So what has brought about this change? And, how will the role of the CSO continue to evolve?

Let's start at the beginning -- with why this job became necessary in the first place.

Connectivity was the catalyst.

The rise of the Internet and the proliferation of mobile devices enabled even small companies to extend their reach beyond traditional physical boundaries to create virtual businesses and execute transactions globally and instantaneously.

Suddenly, because information was now flowing outside closed, highly secured environments, confidential business-critical data was at risk like never before.

And organizations recognized that since they had to operate in this extended world to remain competitive, there was a need for greater security and for someone to take ownership of the issue within the organization.

As time went by and technology raced ahead, security issues grew more complex and more pressing. For most businesses an Internet presence and the ability to quickly transact business online became not merely an attractive option, but rather a business necessity.

Consequently, technology and the availability of IT infrastructures became critical not just for business success, but also for business survival.

As if the burden of responsibility on CSOs wasn't heavy enough, the rise of privacy and security regulation, including Sarbanes-Oxley (SOX) and the security standards of the Health Insurance Portability and Accountability Act (HIPAA), imposed a wide range of responsibilities and demands on companies to verify and safeguard data.

Regulators assigned full responsibility for data protection to Boards of Directors and C-Suite executives. The assignment of responsibility to the highest levels of the corporation clearly indicated its importance.

Naturally, they turned up the heat in the CSO's office. With these changes, the CSO acquired more clout in the organization.

But as business objectives and security imperatives converge, the role of the CSO has continued to transform -- and it is this convergence that will continue to drive the evolution of the role.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Reducing the risk of insider abuse

The potential for insider abuse can never be eliminated completely, but the steps outlined in this white paper can reduce the potential for such abuse. Read on to ensure no one person can alter your operations to their personal advantage or to the detriment of your organisation.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.