Home > Information Security Magazine > Features > Office Politics
EMAIL THIS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Office Politics
by Marcia Savage
Issue: Jul 2007
printer-friendly
< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   8  |   9  |   10  |   NEXT PAGE  >

In fact, more than technical aptitude, future CISOs will need people skills, says Khalid Kark, senior analyst at Forrester Research. That's because they need to get buy-in at the executive level, and also need to educate and train end users about security threats and secure practices.

"CISOs will not be technology experts, they will be more people experts if they want to succeed at their jobs," Kark says.

Not so fast, says Tim Maletic, manager of information security and information services security officer at Priority Health, a Michigan-based health insurance company. He agrees that people skills are essential--a security professional has to be a jack-of-all-trades and deal with many different groups in an organization--but says technical ability is critical too.

"You can't get so far behind the times with what's going on with current technology that you're getting blindsided or are missing opportunities as new projects are coming through and not seeing how they relate to risk for your organization," he says.

Maletic says he finds himself pulled between the two worlds of business and technology. Building a strong team has helped manage that; he can tap his engineer's e...



xpertise with the latest technology.

He and other security officers also are finding ways to deal with the pressure of ever-present auditors. People skills come in handy on that front.

"You want to make auditors your friends. You need to work cooperatively with them," Maletic says. "My internal auditors are very much partners with me. We share information, keep each other in the loop."

IESO's Lewis says auditors shouldn't be treated as the enemy, a misconception common among some in IT: "Audi- tors are there to help you improve your business, not to flame broil you."

However, external auditors can present a different challenge, Maletic notes. In those cases, it's not so much about collaboration as about defining business requirements.

"And making sure that [with] each objective or control being tested, you can reach an agreement with your auditor about the value and not just roll over and let them do it a hundred percent their way," he says.

Regulatory compliance has been frustrating and time-consuming for CISOs, but a framework such as ISO 27001 can help address multiple regulations instead of dealing with them piecemeal, according to a Forrester survey.

< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   8  |   9  |   10  |   NEXT PAGE  >





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts