Home > Security Tips > Risk Management Strategies > Management support – The key to baking security into business processes
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

RISK MANAGEMENT STRATEGIES

Management support – The key to baking security into business processes


Mike Lamkin, CISSP
07.21.2006
Rating: -4.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


For years security practitioners have been trying to convince anyone who would listen as to the importance of IT security, the need for resources, the criticality of defense-in-depth, etc., with wildly varying results where it matters – the traction and legitimate support from C-level decision makers. After years of coming up short, it's time for a different approach.

There are three reasons why IT security might have traction and legitimate support from the C-level decision makers down to the line managers: 1.) A C-level got caught with his hand in the corporate cookie jar and the company is in damage-control mode; 2.) Security has become a requirement by legislative mandate; or 3.) There is legitimate and ongoing cooperation between business managers and the management of IT and IT security.

If you are in the third group, I commend you for your efforts and success. You have reached a point sought after by most of your peers. You are positioned for continued effectiveness by leveraging the equity you've built up in your organization through maintenance and continuing education.

For those playing catch up after an information breach, financial mishap or system compromise, your situation is not without opportunities. But don't let months or years of frustration find a voice. If you give in to the dark side and use your temporary (yes, it is temporary) moment on center stage to force your associates into submission, bending them to your will based on the righteous indignation that has been festering for years of non-compliance, suffice it to say, such victories will be resented and short lived.

On the other hand, you can use such an opportunity to emphasize your desire to understand business needs and help guide the organization into compliance as painlessly as possible – educating management along the way. Help them to understand that by securing their systems and information you can actually help to solidify their business models. If you are working on legislative compliance issues, the situation may be similar – albeit perhaps lacking the sense of urgency and immediacy.

More information

In this archived Q&A, Linda Stutsman offers her insight on how to win management support.

Learn about security management practices in lesson 1 of our free Security School: Training for CISSP certification.

 

Let's examine some of what is necessary to make the situation more palatable from the Security perspective. My cursory mention regarding "understanding their business needs" belies the detail involved in such an effort. For years it has been incumbent on the security professional to constantly reinvent himself. Changing technologies, morphing threats and dynamic environments require security practitioners to constantly learn new technologies, skills, products and solutions. Such is the nature of the task. Now is the time to consider also expanding your business skills.

You've heard the advertiser's refrain, "We must get inside our customer's heads!" This suggests that the goal is to understand what the customer wants and why. If the business side of your organization is your customer, this is equally applicable for you. By understanding what is important to the business managers in your organization and learning to speak about those concerns in language familiar to them, you can start to approach security concerns on friendly turf. Such a tack, if undertaken sincerely, will go a long way toward winning management's support, but is not an effort to be approached lightly.

Many of you are fluent when it comes to routing tables, ACLs, network design, etc. If, however, you find accounting, production issues, sales figures and marketing less than appealing, you may be in for a steep learning curve and find yourself choosing between technical training and business courses. Understanding these concepts beyond simply incorporating 'business-speak' into your approach to security will increase your value to an organization and enhance your ability to communicate on multiple levels. Such an investment will distinguish you from many of your peers and provide you with an enhanced perspective from which to present your security concerns and solutions.

Nominate your peers
SearchSecurity.com is recognizing the achievements of leading security practitioners in seven vertical industries: financial services, telecommunications, manufacturing, energy, government, education and health care. Submit your nominations by Aug. 1 to securityseven@infosecuritymag.com.

Start by learning the industry trends and concerns by familiarizing yourself with the trade publications for your company's industry. For general financial and industrial information, The Wall Street Journal is hard to beat. If you have an in-house library or Web-based learning resource search for courses on finances for non-financial managers or accounting/financial fundamentals. Many public libraries have ebooks available at no cost. Search these out as well. Finally, there are a couple of resources that I have found to be quite useful. Though these are both dated a bit, I liked The Portable MBA in Entrepreneurship (3rd Edition), by William D. Bygrave because, as the title implies, it gives a good and thorough overview of business issues and terminology. I also liked The Inside Raider by A. David Silver because he effectively talks about the need to think entrepreneurially in any organization – and I find that to be a very healthy mindset.

Ultimately, it boils down to finding a way for you to gain credibility outside of the data center and build corporate equity. You must create your own constructive opportunities and show how you can contribute to your organization's business processes.

About the author
Mike Lamkin, CISSP, is an IT security consultant with a global 100 company based in Houston, Texas. Mike has been an IT security practitioner for the last seven years and has been in the IT industry for more than 28 years. Mike has spoken at seminars and conferences, conducted training and authored several articles on networking, security and related issues.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Risk Management Strategies,   Information Security Management,   Business Management: Security Support and Executive Communications,   Security Awareness Training and Internal Threats,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Risk Management Strategies
Breach prevention: How to keep track of data and applications
Information security management hype: Debunking best practices
Monitoring program data and internal controls for risk management
Cloud computing security: Choosing a VPN type to connect to the cloud
Cloud computing security: Routing and DNS security threats
Cloud computing security model overview: Network infrastructure issues
How to align an information security framework to your business model
When to use open source security tools over commercial products
Vulnerability test methods for application security assessments
Security book chapter: Applied Security Visualization

Business Management: Security Support and Executive Communications
Aligning network security with business priorities
RSA council addresses growing security risks in the cloud
How to write a risk methodology that blends business, security needs
Risk management must include physical-logical security convergence
New partnerships, creative thinking help security bust recession
How to align an information security framework to your business model
Service-focused security offers best value to organization
Cybersecurity Act of 2009: Power grab, or necessary step?
Information security skills must include communication, expert says
Mimic the IBM approach to security at RSA

Security Awareness Training and Internal Threats
Creating a HIPAA employee training program
Successful rogue antivirus hinges on social engineering
External attacks start with unintentional mistakes, survey finds
Security technologies fail to address insider threat management
Data breach avoidance begins with security basics, panel says
Monitoring program data and internal controls for risk management
Software security threats and employee awareness training
Twitter risks, Facebook threats trouble security pros
Social engineering training could disrupt botnet growth
How to write a risk methodology that blends business, security needs

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
security  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts