issa, ottawa, greg young, chris ellis, scott wright, barton mckinley, challenges, 2012, collaboration, executives, policy efficiency, siem, awareness, training, mobile, cloud
You are not logged in. Access is limited. Login or see membership information. • Streetwise Security Zone Community

To see the list of all blogs, including Scott Wright's Security Views Blog and the Streetwise Security Zone Podcast click HERE. You also can subscribe via an RSS reader, or check the "Watch This" box in the left column to receive news by email of new articles.


Watch this Blog Notify me by e-mail any time a new post is made to this blog.

Scott Wright's editorials on a variety of security issues for non-technical business managers and home computer users. Please feel free to comment and help spread the word that managers need to think about their information security risks.

The Virus Time Machine (e-Book)
Product ID: 00000007

... What You Need to Know (and Wish You Knew Before) About Removing Virus and Malware Infections Before you start down the path of trying to fix a virus infection on your computer, you should really understand what's invol ... More »

Non-Member Price: $4.99

January 2012 Posts

Archives

  Scott Wright's Security Views
Blog Entry

Where should security effort be focused these days?

Friday, January 27th 2012 @ 7:01 AM (not yet rated)    post viewed 522 times

Yesterday, I was on a panel at the Information Systems Security Association’s Ottawa Chapter meeting. We had a great discussion on the security challenges of 2012. Clearly, there is a lot of concern among security professionals around the threats and vulnerabilities related to mobile devices and about outsourced data and services that are said to be in “the Cloud”. The other members of the panel included Greg Young (Gartner) and Chris Ellis (McAfee). They had some great insights on what organizations are doing, and should be doing, about these issues.

I think the result of the discussion was a signal to businesses (including government organizations) that we need a mix of returning to fundamentals of security and increasing efficiency overall. We highlighted the need to step back and identify gaps, and to focus on establishing and communicating effective policies that are clear and easy to follow.

We also need to do “more with less”, or try to work smarter to see where some of the wasted effort can be cut back (including my cherished security awareness posters). On that note, we did have some discussion around security awareness education and training. The entire panel, especially Chris and I, endorsed awareness training because it covers a broad range of risks to which all staff can become more sensitive - with real life examples of how this has been successful. Greg felt that Posters were seen as being something that can tend to become invisible, or fading into the background, as “wall ornaments” that nobody pays attention to. This is why I prefer that, if you do use posters, you simply need to move them around to unexpected locations, or change them on a frequent basis. People will notice.

The topic of communicating with executives is one that I think is extremely important. How do you describe security risks and justify security spending to executives. Some felt that it should be worked into the "plumbing" of everyday operational business processes, so that it doesn't "look like" security to the executives. While I believe this is a great objective, I have a concern that this it is likely to take a long time to change the organization in this direction. In the meantime, we shouldn't shy away from trying to communicate the importance of IT security risks to executives and senior management as soon as possible, but in terms that they can understand - focusing on the business consequences of the biggest risks, should they materialize.

There was also a strong theme of collaboration in this discussion. We each have varying degrees of experience with different security and business issues (like justifying security spending to executives), and the sooner we are able to share our experiences and lessons learned, the better we can secure our business environments.

The ISSA Ottawa Chapter is a smart, fun and vocal group of professionals. I was proud to be on this panel. Our next meeting is a big one on February 15, 2012, and focuses on Women in Security. The event features a high profile speaker, Marene Allison, VP & CISO of Johnson and Johnson, as well as Carol Osler, VP at TD Bank.

I am now offering monthly briefings, tailored to organizations that want to build and sustain security awareness for staff. Just because your security team is too busy to do its own training and awareness doesn't mean you can't have an economical way to address human security risks. Please call or email me at the coordinates below...

Scott Wright

The Streetwise Security Coach

Join the Streetwise Security Zone at:
http://www.streetwise-security-zone.com/join.html

Phone: 1-613-693-0997
Email: scott@streetwise-security-zone.com
Twitter ID: http://www.twitter.com/streetsec

To receive weekly security tips and other notices about helpful content available on this site, please make sure you are on my list by clicking HERE, and entering your name and email address.

 

 

Site Meter

 rate this post: very bad poor average good fantastic!
Comments