Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Diverse skills needed for CSO function, group says

The job requires understanding of a range of IT and other risks, says ASIS International

December 5, 2003 12:00 PM ET

Computerworld - A knowledge of information security risk management is just one of the many skills a chief security officer needs for crafting, influencing and directing an effective organizationwide protection strategy.
Increasingly, the job also calls for an understanding of issues as diverse as emergency preparedness, crisis management and response, physical security, disaster recovery, and privacy and regulatory matters. That's the assessment of Alexandria, Va.-based ASIS International, a 33,000-member group of security professionals that this week released draft guidelines that companies can use when developing CSO positions.
"There's been a lot of discussion on the need for organizations to create a centralized governance function for many areas of risk," said Jerry Brennan, president of Vienna, Va.-based Security Management Resources Inc. and one of the drafters of the document.
The guidelines are the result of an attempt to give a formal definition of the scope, responsibilities for reporting relationships and experience needed to do the job, he said.
"There wasn't much available that addressed the pulling together, from a governance perspective, of all of the areas of security risk that an organization faces," Brennan said. "So we decided to try and craft a document that would be broad-based and truly represent what the CSO position would be in an organization."
The ASIS guidelines come at a time when a growing number of security professionals say there needs to be a top-level management position to oversee all aspects of operational risk. "I have always found it preposterous to suggest that there are separate disciplines that require separate management" when it comes to operational security, said Dennis Treece, director of corporate security at the Massachusetts Port Authority in Boston.
For example, installing a privacy officer who is separate from the rest of the security team only "fragments the effort and ensures that the physical and virtual aspects of privacy have to be laboriously coordinated," Treece said. The same is true when it comes to having separate chief information security officer and CSO functions. "Having been both separately and now both at the same time, I can state with confidence that combining them makes the most sense," he said.
Even so, security professionals agree that only a relatively small number of companies have created a formal CSO function because of the substantial political and organizational challenges that need to be overcome in doing so.
The popular notion of the CSO being in charge solely of IT and physical security functions has also limited the effectiveness of the role, said David W. Stacy, global IT security director



Jump to comments

Security

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...