NewsFactor's CIO Today FIND:      
  Daily Briefing for Technology's Top Decision-Makers White PapersNewslettersSign In



January 22, 2006
Updated Daily

CIO Today

Home/CIO News
CIO Interviews
Business Briefing
E-Business
Infrastructure
Integration
Customer Relations
Data Storage
Network Security
Wireless Internet
Small Business
Worldwide Tech
Science & Innovation
Web Services
CIO Today Magazine


Top Tech News
Home
Hardware
Software
World Wide Web
Personal Technology
Tech Trends
Science
Product Reviews
Business Briefing for Geeks
Free Newsletters
Top CIO News
 
Contact Center Industry Alert
 

Advertisement
Compliance
3Com TippingPoint™ IPS.

Security, Compliance Prompt CISO Focus

Security, Compliance Prompt CISO Focus November 30, 2005 11:14AM

Increasingly, corporate security goals aren't about information security but about information assurance, which deals with issues like data availability and integrity, said Jane Scott-Norris, chief information security officer (CISO) at the U.S. Department of State.


Reports tell you what has happened in the past. Forecasts tell you what might happen in the future. Progress Apama tells you what is happening right now. Learn how to gain insight into your current operations. Download “The Need for Speed and Agility: Event Stream Processing for Event-Driven Business”


Regulatory compliance issues and concern over data compromises have brought information security Relevant Products/Services from Microsoft issues to the forefront in corporate boardrooms, according to a panel of I.T. security managers at the Computer Security Institute.

That trend is forcing security managers to adopt a more business-oriented approach to creating security strategies.

Selling management on the need for information security has become easier for I.T. managers because of privacy threats, data piracy and other issues, said Terri Curran, director of information security at Framingham, Mass.-based Bose Corp. "In a sense, the road has been paved more for us. Management knows they've got to have security."

However, security managers often tend to better understand technology issues than they do risk management topics, said Jack Jones, chief information security officer at Nationwide Mutual Insurance Co. in Columbus, Ohio. As a result, their efforts are often misaligned with business goals, he said.

"Perfect security is not achievable," Jones said. "At the end of the day, [the security function] is about managing the frequency and magnitude of loss."

That goal requires that security managers do a better job of putting technology issues into a business context, Jones said. That's a significant challenge for security officers, he added.

Increasingly, corporate security goals aren't about information security but about information assurance, which deals with issues like data availability and integrity, said Jane Scott-Norris, chief information security officer (CISO) at the U.S. Department of State. Thus, organizations should focus on risk management as well as risk avoidance. "You have to be able to evaluate risks and articulate them in business terms," Scott-Norris said.

Jennifer Bayuk, CISO at New York-based Bear, Stearns & Co., said that it's also important for security managers to demonstrate their value to an organization especially because security is often seen as a cost center offering little return on investment. "If you can't demonstrate what you are doing, it doesn't count," Bayuk said.

Looking ahead, Bayuk predicted that CISOs will have two distinct career paths: a technology-focused position that reports to the CIO, and a business-focused role that works with chief risk officers.



© 2006 Computerworld. All rights reserved.
© 2006 CIO Today. All rights reserved.

Advertisement


 More on this topic...
1. The Long Arm of Compliance
2. Danger Lurks for Stored Data
3. Building Around Compliance
4. The Awful Truth About Compliance
5. Tops of the SOX Applications

 Related Topics  Latest News & Special Reports

  NTT Launches IPv6 Firewall Service
  VoIP Cures Agency's Telecom Ills
  Microsoft Cuts Price, Still Lags in CRM
  Siebel Sees a World of Components
  CIOs Confident Now, Wary of Future

 Sponsored Links

3Com’s TippingPoint™ IPS: Plug it in.

Progress® Apama® lets you gain insight into your current operations.

Windows Server vs. Linux SuSE: Read the Security Innovation study.

Outsourced Security Trends in Messaging. Download Whitepaper now!

DualPath Outdoor Wireless Bridges. Get online price estimates.

Special 2 for 1 Offer & Free IDC Virtualization White Paper from HP.

SAN Connectivity in Virtualized Server Environments from Emulex

Secure your backup media with Brink’s. Download FREE White Paper

Join AMD—online—for the latest in the AMD In the Enterprise series.

Best in class enterprise IT solutions from 3Com

Living in L.A.? Click here for Sales, Journalism & I.T. JOBS.

White Papers
3Com’s TippingPoint™ IPS: Plug it in.

Progress® Apama ®: monitor, analyze & act on event stream data.

Outsourced Security Trends in Messaging. Download Whitepaper now!

DualPath Outdoor Wireless Bridges. Download White Paper.

Secure your backup media with Brink’s. Download FREE White Paper

Read a white paper about best in class VoIP solutions from 3Com.

More White Papers...

Security Spotlight

Online Banking: How Safe Is Your Money?
In response to the growing threat of online fraud, financial institutions around the world are stepping up their user-authentication systems to make banking more secure.

FBI: Most Companies Get Hacked
Almost nine out of ten companies had a computer-security incident last year, according to a new report from the Federal Bureau of Investigation.

Microsoft Issues First Vista OS Patch
Microsoft has issued its first security patch for Windows Vista. The patch repairs the same graphics-rendering flaw discovered in Windows XP late last month.

Advertisement
Navigation
CIO Today
Home/CIO News | CIO Interviews | Business Briefing | E-Business | Infrastructure | Integration | Customer Relations
Data Storage | Network Security | Wireless Internet | Small Business | Worldwide Tech | Science & Innovation | Web Services
Compliance |
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Contact Center Today

Services:
How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2005 CIO Today. All rights reserved.