Home > Information Security Magazine > Features > CISOs, human resources cooperation vital to security
EMAIL THIS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

CISOs, human resources cooperation vital to security
by Marcia Savage
Issue: Jan 2009
printer-friendly
< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   NEXT PAGE  >

BRIDGING GAPS
At Sonneborn, Orozco works across the hall from the IT director in the company's Petrolia, Pa. office, which makes communication easy when security issues come up (see "Lost in Translation," below). The company, which outsources its IT functions, counts about 160 employees in Pennsylvania and about 300 worldwide.


[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE] [IMAGE] Lost in Translation [IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
Don't use jargon when communicating with human resources.

In working with human resources professionals, security professionals should make sure they're "talking in a language the HR person can understand," says Melody Silberstein, senior vice president of human resources at insurance brokerage Woodruff-Sawyer & Co.

"Sometimes my IT person and I are talking two different languages," she says. "If I don't understand what he's saying, I don't understand my risk."

Using laymen's language is critical in communicating the risks associated with newer tools that employees use, such as instant messaging, and also in supporting proposed equipment purcha...



ses, she says.

Since she's been immersed in security, Silberstein has become aware of the security issues around outsourcing. IT security professionals can help HR teams understand the risks involved when they outsource and questions they need to ask third-party vendors, she says.

Lee Kushner, founder and CEO of information security recruiting firm LJ Kushner and Associates, says security professionals can help HR pros who are focused on recruiting to help them understand what type of person to hire. "A big complaint of security professionals is, 'HR doesn't understand what I'm looking for'," he says. "But if the security professional would actually sit down with the recruiter and give the recruiter a bit of an education on how to find or what to look for, you would definitely have more successful recruiting."

Khalid Kark, principal analyst at Forrester Research, says security and HR professionals need open minds when they begin working together.

"Usually they have preconceived ideas around this is what HR or security is going to do," he says. "Go in with the perspective that the other is there to help the organization. Don't go in with the notion that HR doesn't know or care about anything about security."

--MARCIA SAVAGE


[IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE]
[IMAGE]

< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   NEXT PAGE  >





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts