Skip the navigation

Risk management seen as key to IT security

Merrill Lynch's security chief outlined his approach at the Premier 100 event

By Kathleen Melymuka
March 10, 2004 12:00 PM ET

Computerworld - PALM DESERT, Calif. -- In IT security, emotional reactions, panic and legislation are counterproductive. But intelligent risk management can enable organizations to face an uncertain future optimistically.
That was the message from Merrill Lynch & Co.'s security chief to attendees at Computerworld's Premier 100 IT Leaders Conference here yesterday.
David Bauer, first vice president and chief information security and privacy officer at Merrill Lynch, gave his audience a historical perspective on the evolution of IT security, starting with the Morris worm attack of 1988. That attack took the Internet by surprise, he said. There were no tools to fight back and no source of reliable information. Responses were uncoordinated, and the result was "complete havoc," Bauer said.
He contrasted that with the Mydoom attack last month, when Merrill Lynch combined good tools with a coordinated and carefully planned response to understand and contain the threat after just one infection. That attack, he said, was "just another event."
"The difference between then and now is tremendous," Bauer said, "and preparation is the key." Preparation requires a focus on risk management, intelligence-driven prevention and response, security at the data-object level and a focus on both the corporation and the individual consumer of technology.
"It's easy to get somebody's password, so make the damage that can be done by an individual as small as possible," he said.
Bauer also suggested that, since IT security is fundamentally a technology problem, it should be handled within the IT operation.
Merrill Lynch's IT security strategy is built around strong organization; threat management, including intelligence, planning and instant response; comprehensive security services; attention to public policy, including active attempts to educate legislators; and agile response to the changing risk environment, he said.
A key component of that strategy is dynamic risk assessment. Using tools such as scanners, log analysis, risk metrics and asset inventory, Merrill Lynch's security group produces a biweekly security brief analyzing and prioritizing current threats. "That allows us to go from a circle-the-wagons approach to intelligent risk management," Bauer said.
In response to audience questions, Bauer said that as a percentage of the IT budget, Merrill Lynch's security service costs less than that of any competitors. "It's not about how much you spend but how well you spend it," he said. "We're not making vendors rich, but if we buy something, we use it."
He also noted that about half of his spending is advisory, helping the company build secure systems, while the rest goes toward risk management, prevention and response.
Bauer addressed the problem of legislation, which he said drives up costs and takes resources away from actual risk mitigation. "Part of our strategy is our Legislative Watch," he said. "We try to keep ahead of legislators and influence them, if not to cancel legislation at least to word it properly." He urged all corporations to do the same.
Looking ahead, Bauer predicts that the threat picture will be "interesting." But with defenses built around thoughtful planning, he said, "I'm optimistic about our chances for success."
Complete preconference survey results (registration required)

Read more about Security in Computerworld's Security Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs