How to manage a total security package
I'm a systems engineer and am interested in moving to infosec. Ideally, I would like to be part of a group involved in managing a total security package or one that deals with all aspects of this field. Does this position exist, or is it typically broken up into different technology-based areas such as network, ID, application, etc?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

While I am not 100% clear you what are referring to when you state, "managing a total security package," but these positions do exist.

A CISO or CSO has to "manage a total security package" within an organization, which includes technology, policies and procedures, personnel, business processes and more. A person who will effectively fulfill one of these roles has to be extremely well-rounded in all aspects of security and motivated to continually learn and be challenged.

Since you are a systems engineer, you may be referring to a "total security package" as a holistic technical security environment. This environment would consist of access control technologies, firewalls, IDS/IPS, antivirus and more. A security administrator would be responsible for managing this type of environment, which to be clear, is different than a network administrator. A security administrator is more concerned with who is accessing company assets and what they are allowed to do with those assets. On the other hand a network administrator is responsible for monitoring the availability of the network -- the nodes and devices that make up the network -- and has to ensure that it is always up and running and performing properly.

While the security team can be made up of individuals who specialize in specific technologies and applications, the security administrator has to understand all of them, and has to ensure that they all work together in a synergist manner.

This was first published in February 2006