Home > Ask the Security Experts > Expert Archive: Security Management Questions & Answers > How can a CSO take ownership of a security program?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How can a CSO take ownership of a security program?

Mike Rothman, past SearchSecurity.com expert EXPERT RESPONSE FROM: Mike Rothman, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 02 February 2007
When it comes to information security, Department of Defense organizations have cut-and-dry requirements to meet. Most DoD organizations I have worked with, however, feel that information security is the IT department's responsibility. How does a new chief security officer (CSO) get an organization to take ownership of the security program?

>
Information security is everyone's responsibility. Every employee must do the right thing and protect the data and systems within his or her control. But it is the chief security officer (CSO) who is accountable for the results of the security program. Hopefully, the difference is clear.

It's also important to note that the CSO is a position of influence, as most of the resources needed to successfully run a security program reside in multiple groups. For instance, the network operations team tends to run the firewalls and IPS gear. The data center managers are responsible for patching the servers and securing the databases. Yet someone has to assume responsibility to make sure that everything works together, business systems remain available and data is appropriately protected.

What I'm alluding to here is that every CSO needs to manage the security PROGRAM, and they do this without directly controlling people or tools. Right, that's a tall order.

As I describe in the Pragmatic CSO, the job of the CSO is now more about persuading senior managers and IT colleagues to implement good security practices. This is a multi-stage process that is radically different than one that most security professionals have used in the past. But given the new reality of such a wide distribution of resources, most CSOs have no choice but to act more Pragmatically.

Those in the DoD need to express security within the context of the military business, just as those in commercial enterprises need to make security relevant to their business operations.

More information:

  • Should capable network managers stretch their duties into the security space, perhaps acting more like a CSO? Contributor Shon Harris explains.
  • Make sure your information security governance program is focused and effective.


  • BROWSE BY TAG
    Expert Archive: Security Management,   Information Security Policies, Procedures and Guidelines,   Information Security Management,   Business Management: Security Support and Executive Communications,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Expert Archive: Security Management
    What is the GISP certification and how does it compare to the CISSP certification?
    Using a QSA to write up a PCI DSS report on compliance (ROC)
    How can gap analysis be applied to the security SDLC?
    Comparing cheap security products and appliances to costly appliances
    What are some tips on protecting my security budget in a poor economy?
    What value do research firms provide to their subscribing enterprises?
    What certificate offers the best ROI for an IT project manager?
    Is insider activity or outsider activity a bigger enterprise threat?
    How does information security prevent fraud in the enterprise?
    Differences between an SAS 70 data center and a Tier III data center

    Information Security Policies, Procedures and Guidelines
    Health Net breach failure of security policy, technology
    How to protect distributed information flows
    Essential guide: Pandemic planning for H1N1
    Whitelists, SaaS modify traditional security, tackle flaws
    Melissa Hathaway urges more cooperation, government attention to cybersecurity
    Reuters: Obama ready to select cyber security czar
    How a corporate Twitter policy can combat social network threats
    Should enterprises be concerned with Twitter in the workplace?
    Information security management hype: Debunking best practices
    Data breach avoidance begins with security basics, panel says

    Business Management: Security Support and Executive Communications
    Cost of security, IT management add up at healthcare facilities, study finds
    Secure your remote users in 2010
    Layoffs prompt insider threat fears, cybersecurity survey finds
    How to use Internet security threat reports
    Aligning network security with business priorities
    RSA council addresses growing security risks in the cloud
    How to write a risk methodology that blends business, security needs
    Risk management must include physical-logical security convergence
    New partnerships, creative thinking help security bust recession
    How to align an information security framework to your business model

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    defense in depth  (SearchSecurity.com)
    non-disclosure agreement  (SearchSecurity.com)
    security policy  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts