Home > Ask the Security Experts > Security Management Questions & Answers > How can a CSO take ownership of a security program?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How can a CSO take ownership of a security program?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 02 February 2007
When it comes to information security, Department of Defense organizations have cut-and-dry requirements to meet. Most DoD organizations I have worked with, however, feel that information security is the IT department's responsibility. How does a new chief security officer (CSO) get an organization to take ownership of the security program?

>
EXPERT RESPONSE
Information security is everyone's responsibility. Every employee must do the right thing and protect the data and systems within his or her control. But it is the chief security officer (CSO) who is accountable for the results of the security program. Hopefully, the difference is clear.

It's also important to note that the CSO is a position of influence, as most of the resources needed to successfully run a security program reside in multiple groups. For instance, the network operations team tends to run the firewalls and IPS gear. The data center managers are responsible for patching the servers and securing the databases. Yet someone has to assume responsibility to make sure that everything works together, business systems remain available and data is appropriately protected.

What I'm alluding to here is that every CSO needs to manage the security PROGRAM, and they do this without directly controlling people or tools. Right, that's a tall order.

As I describe in the Pragmatic CSO, the job of the CSO is now more about persuading senior managers and IT colleagues to implement good security practices. This is a multi-stage process that is radically different than one that most security professionals have used in the past. But given the new reality of such a wide distribution of resources, most CSOs have no choice but to act more Pragmatically.

Those in the DoD need to express security within the context of the military business, just as those in commercial enterprises need to make security relevant to their business operations.

More information:

  • Should capable network managers stretch their duties into the security space, perhaps acting more like a CSO? Contributor Shon Harris explains.
  • Make sure your information security governance program is focused and effective.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    Is it against HIPAA regulations to permanently store sensitive information?
    Two-tier distributed systems vs. three-tier distributed systems
    How to prevent software piracy
    How do ISO 17799 and SAS 70 differ?
    Has FFIEC made any VoIP-specific mandates?
    What is the best way to administer exams to students via computer?
    Should computer exams be transmitted as PDF files or Word files?
    Is it against HIPAA regulations to display client names?
    Getting started on a career in penetration testing
    Are there security management products that can track compliance objectives?

    Creating and Managing Information Security Policies
    Security Awareness Training Essential Part of Infosec Program
    How to lock down instant messaging in the enterprise
    Worst practices: Bad security incidents to avoid
    Thompson calls for marriage of data and security management
    Companies Collecting Too Much Customer Data Increase Exposure
    Interview: Arizona CISO David VanderNaalt
    Incident response success in five quick steps
    Social networking Web site threats manageable with good enterprise policy
    IT GRC: Combining disciplines for better enterprise security
    Security management in 2008: What's in store
    Creating and Managing Information Security Policies Research

    Management Support for Information Security
    Results Chain for Information Security and Assurance
    Information Security Blueprint
    Learn from NIST: Best practices in security program management
    CISOs adapt as compliance requires strategic thinking
    The New School of Information Security
    Security, Privacy Offices Must Combine Resources
    E-discovery management: How IT should interact with the legal team
    IT GRC: Combining disciplines for better enterprise security
    Security Wire Weekly: Shrinking IT security budgets
    Are there security management products that can track compliance objectives?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    defense in depth  (SearchSecurity.com)
    non-disclosure agreement  (SearchSecurity.com)
    security policy  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts