Home > Information Security Magazine > Columns > Information security officers need to sharpen their risk management skills
EMAIL THIS LICENSING & REPRINTS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Information security officers need to sharpen their risk management skills
by Dave Shackleford
Issue: Nov 2007
printer-friendly
licensing & reprints
< PREV PAGE   |   1  |   2  |   NEXT PAGE  >

For the last few years, we've heard CISOs need to improve their business skills. But many of today's security managers are lacking another critical discipline: risk management. As compliance initiatives become more ingrained in our business culture, and security is playing a role in most IT disciplines, there is a need for an internal "trusted adviser" who is able to translate the nuances of IT initiatives into real risk metrics. For example, security controls have traditionally been knee-jerk purchases or based solely on technical opinions and interest. Security management needs a more viable rationale for secu- rity design and implementation, as well as a more consistent framework for influencing business decisions and explaining why security is integral to business strategy.

A good friend who is a CISO explains the situation well. In his view, a CISO should really be called a CRO--chief risk officer--or report to one, and a major element of the position should be policy management--establishing guidelines and policies that adequately capture the organization's risk tolerance, and then working with operational management to ensure the policies are adhered to. The security profession talks a lot about policy these days, but we tend to omit that critical detailed risk analysis factor. Unless today's CISOs learn this important discipline and become adept at articulating it to senior management, the role of a CISO as we know it may very well become extinct.

< PREV PAGE   |   1  |   2  |   NEXT PAGE  >





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts