- 1
- 2
- < previous
Who's in charge?
Establishing a structure is all well and good, but even when information is recognized as a high-value asset, many organizations still stuff the responsibility for its definition and protection down into low-level records and IT roles. This simply doesn't work, because those roles often don't have the authority to properly implement or manage the controls, and the new responsibilities take second place to existing job tasks.
For example, information classification (download PDF) is required in order to qualitatively categorize and determine what controls are appropriate to protect information, but does an IT director have the authority to mandate a classification scheme for an organization? Such attempts are often dismissed as data classification, when in fact the effort ought to apply across business units, HR, legal, records management, and other parts of the organization.
Likewise, would it be appropriate for IT to change the business rules for access to information because of a technical limitation or new feature? It's unfortunately common for organizations to become enamored with new connectivity features in a data repository or interface, and use that to open up remote access or data interchange for remote partners -- but just because you can doesn't mean you should. Access changes should be driven forward by business need, and back by risk. Technical capability is a secondary question for IT.
A limiting factor is that the larger cycle of information includes things from requirements-gathering, to governance, to metrics, to process controls, to technical controls, to audit -- and then a loop back to revision of requirements, governance feedback and adjustment, and so on, again and again. IT owns the middle of this sequence, but not the requirements, audit, or other beginning or end tasks. Someone needs to lead the beginning and end to ensure the middle (the IT part) connects and aligns with the rest.
This is why IT managers or directors are a poor choice for information governance leaders: one can't simultaneously be responsible for the implementation of controls and the audit of whether those controls work properly. A governance leader might be a senior manager or director that handles information in all forms (such as physical records management, as well as electronic), or an executive responsible for compliance. But putting information governance program establishment or reform under the IT organization makes it control-focused, not asset-focused or performance-oriented.
Being serious
After a while, the emergent pattern one sees is that information governance and effective security is equivalent to proper business process. Security nirvana is achieved when security controls asymptotically become indistinguishable from right and proper business process, and alerts from business process variances and security control breaches are one and the same.
Bruce Schneier recently espoused the idea that security has to be "sold" on one side of the balance sheet or the other; either it enhances the profit centers and adds to the bottom line, or reduces actual loss. However, when information security controls end up being close parallels or integrated within existing business processes, it means less selling, less disconnection, and fewer moments where executives perceive information governance as some kind of power grab from IT.
When information governance is treated like any other critical asset control process, it's possible to move forward and make security less independent of the business. And that's what we're after, isn't it?
Jon Espenschied has been at play in the security industry for enough years to become enthusiastic, blase, cynical, jaded, content and enthusiastic again. He is Director of Security Consulting at Consciere, and continues to have his advice ignored by CEOs, auditors and sysadmins alike.
- 1
- 2
- < previous
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Gaining Competitive Advantage Through Enterprise Planning
IT Service Management Needs and Adoption Trends: An Analysis of a Global Survey of IT Executives
Best Practice in Building an Integrated Information Management Strategy
How to improve employee productivity in small and medium businesses
Data grids and service-oriented architecture
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
The state of Middleware
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 2008-12-02 09:56:00+11
CRM your salespeople will love
Winning over the sales department and obtaining buy-in at all levels is crucial to the success of any CRM initiative. Discover how you can let salespeople work how they want to and reduce their administrative burden with the latest CRM technology.












