Access "CISOs, human resources cooperation vital to security"
This article is part of the January 2009 issue of How to be successful with your security steering committee
Fifteen years ago, when human resources executive Anita Orozco needed to hire or fire an employee, involving IT probably wasn't on her to-do list. But the Internet boom and employees accessing corporate systems from virtually anywhere changed that. "Now it's definitely more important, whether getting a new employee set up with access to systems and software, or getting someone turned off," says Orozo, director of HR at Sonneborn, a manufacturer of refined hydrocarbons. "The turning off has become especially important. Generally, we'll give as much notice as possible to the IT staff so they can do what they need to do to protect the company." Like others in her field,Orozco finds it increasingly important to work regularly with technology managers to ensure corporate data is secure. In the information age, human resources professionals are teaming up with their counterparts in IT security to investigate potential Web or email policy violations by employees, develop security policies and procedures, and plan for disaster recovery. Bringing human resources and ... Access >>>
Access TechTarget
Premium Content for Free.
What's Inside
Features
-
-
CISOs, human resources cooperation vital to security
CISOs work closely with human resources to investigate potential Web or email policy violations by employees, develop security policies and procedures, and plan for disaster recovery.
-
Information security steering committee best practices
Security steering committees bring HR, finance, legal, IT and audit to the same table, helping facilitate the integration of information security into lines of business.
-
Product Review: GoldKey Secure USB Token
The GoldKey Secure USB Token works with Windows and Macintosh operating systems to provide a secure place to stash encryption keys for virtual disks. By keeping encryption keys on a small, removable USB token, GoldKey simplifies the task of locking away important information on laptops and encourages good security behaviors.
-
Product Review: Trend Micro Worry-Free Business Security 5.0
Trend Micro Worry-Free Business Security (WFBS) delivers comprehensive client/server protection for small businesses against a variety of Web threats for Microsoft Windows 2000/XP/Vista, Small Business Server 2003/2008 and Exchange Server.
-
Security services: Mimecast's Unified Email Management
Mimecast offers a multifaceted SaaS package as demand for email services grows and the vendor landscape consolidates.
-
Internal auditors and CISOs mitigate similar risks
Internal audit and information security may often find themselves at odds, but in the end, their respective goals are the same.
-
CISOs, human resources cooperation vital to security
-
-
Implement security and compliance in a risk management context
CFOs live in a world where risk management is the lingua franca. CISOs have to join the conversation.
-
Product Review: Cenzic Hailstorm Enterprise ARC 5.7
Web application security has moved from a niceto- have to a must-have requirement, for data protection and compliance. Cenzic's Hailstorm, which we last reviewed in 2005, reflects the growth in the depth and maturity of Web application vulnerability assessment software.
-
Product Review: Hedgehog Enterprise 2.2
Eight years after the release of Microsoft SQL 2000, we're still looking for help from bolt-on security product vendors to harden and protect critical production database servers. Sentrigo's Hedgehog Enterprise 2.2 is designed to monitor and protect against known and unknown database threats.
-
Rising Profile
Security had the attention of SMB execs; the time for facilitating integration is at hand.
-
Tests point out antivirus shortcomings
Tests suggest antivirus software is somewhat ineffective against today's malware strains.
-
The evolving role of the CIO involves IT and security responsibilities
Technology executives focus on elevating information security in the enterprise.
-
Implement security and compliance in a risk management context
-
Columns
-
Insider threat mitigation and detection: A model for committing fraud
Risk managers should know in order to commit fraud, or any other improper action, an attacker needs access, knowledge/ability and intent.
-
Interview: Protecting data and IT assets in a recession
The Republic First Bank information security officer offers guidance on maintaining a security program in lean economic times.
-
Security steering committee force CISOs to connect with the business
Security steering committees provide a forum for security managers and business leaders to discuss security and privacy issues and explore compliance implications of new projects and technology purchases.
-
State Data Breach Notification Laws: Have They Helped?
There are more than 40 state notification laws, but how have they impacted the security of sensitive data? Our two experts debate the issue.
-
Insider threat mitigation and detection: A model for committing fraud
More Premium Content Accessible For Free
Unlock new pathways to network security architecture
E-Zine
Network security architecture is showing its age at many organizations. With new technology, different data types, and use of multi-generations of ...
Emerging threat detection techniques and products
E-Handbook
Advanced persistent threat (APT) has been a used and abused term in the security industry, but security experts say targeted attacks are a growing ...
The rapid evolution of MDM solutions
E-Zine
Mobile device management (MDM) continues to grow at a feverish pace, both in terms of adoption and mobile security features. BYOD policies, and the ...
Security Management Strategies for the CIO