RE: InfoSec Importance



I am trying to convince my management of the importance of having a
security officer in the enterprise. I have googled the topic, but not
much was found. I would really benefit from your suggestions on how to
approach the management.

They *may*, just possibly, have convinced themselves that "security is
everybody's job", but the fact is that everyone else is already doing some
other job and so the actual effect is "security is nobody's job". Unless
the enterprise is really really small, it needs somebody whose primary
responsibility is security.

Hopefully, you don't need to just scare them into agreeing that security
is a necessary part of doing business -- they should already be at that
point. It's just that there needs to be a person dedicated to making sure
that it happens, a central point of contact between IT, HR, counsel,
facilities, loss prevention, audit, etc, so that these various efforts
reinforce each other instead of duplicating efforts or undermining each
other.

Experience suggests that there are two common languages which will get
the attention of most managers and executives: money and jail. While a
security officer can assist with compliance efforts (stay out of jail),
the main thrust should be on reducing liability and risk. [Make it clear
that the Security Officer is, first and foremost, a *business* position
and not a *technology* position. Technical literacy is going to be
important, but it needs to be filtered through an understanding of
business priorities and costs/benefits.]

David Gillett
CISSP CCSE CCNP



Relevant Pages

  • RE: [Full-Disclosure] Where to start
    ... security officer is more of a complience officer, he makes sure that all the users, admin and other it staff stick to the policies created. ... When there are posts on lists they ... > people keep track easily with up to date best practices and not get ...
    (Full-Disclosure)
  • Re: InfoSec Importance
    ... So to answer your question, bringing in a big-gun CSO type isn't where to start with your management, but security occurs when something goes wrong, and they start pointing fingers at the person who said "We need a CSO" ... security officer in the enterprise. ...
    (Security-Basics)
  • Re: New FreeBSD Security Officer
    ... > I asked the FreeBSD Core Team to offer the security officer role to ... Thanks, Jacques, for the words of introduction. ... Second, while I am taking over as Security Officer, I won't be changing ... have been discussed for several months now -- but on the whole FreeBSD ...
    (FreeBSD-Security)
  • New FreeBSD Security Officer
    ... Security Officer for the past 3+ years. ... the FreeBSD Security Team members, ... I asked the FreeBSD Core Team to offer the security officer role to ... Thanks for everyone's support over the years, ...
    (FreeBSD-Security)
  • RE: Is IDS/IPS worthless?
    ... primary business is theirs, and other people's money, calculate technology ... role and costing of technology in a business. ... Different businesses have different teams that look into the value of risk ... Most banks now have IT security savvy staff within their audit teams - I ...
    (Focus-IDS)