Security Manager's Journal: A reality check for the department's maturity
An assessment of the information security department shows that it still has a lot of growing up to do.
Computerworld - I thought I was a security adolescent, but I'm really just a toddler.
Trouble Ticket
Many IT managers can probably tell from that statement that I have been looking into maturity models. I did that at the request of our CIO, who asked all of his department managers to develop a maturity model and identify where we are. Perhaps the topic came up at a conference he attended, but no matter; I had never assessed the maturity of my department at my current company.
My first step was to turn to the Internet to try to find the maturity model that could best help me measure our security program against industry standards. I wanted something that would let me communicate the level of our security maturity in one slide.
I soon found that there are a lot of models to choose from. They range from the complex, requiring lengthy calculations and surveys, to the fairly simple.
Taking into account time and resources, I chose the Gartner Security Maturity Model, making a few modifications of my own. The Gartner model segments maturation into phases: Blissful Ignorance (or what I call the initial phase), Awareness (or the developmental phase), Corrective Action (or the define and manage phase) and Operational Excellence (or the optimized phase). According to Gartner, about half of all companies are in the Awareness phase, and only 5% ever reach Operational Excellence. In other words, most companies know where their weaknesses are but are not yet taking action to correct them.
As I worked my way through the questions that Gartner provides to help clients position themselves on the maturity scale, it became painfully obvious that my security program is not as advanced as I had thought.
Sure, we've spent a lot of money deploying some of the standard buzzword technologies: SIEM, DLP, NAC, file encryption, IPS, content filtering, multifactor authentication, spam filtering, endpoint protection. I have developed a comprehensive set of policies based on ISO 27001 and created awareness training as well as various procedures and processes. But with many of these technologies, we are still in our infancy in terms of capabilities, coverage, deployment and user acceptance.
For example, while we have deployed data leak prevention technology (that's the "DLP" in the list above) to detect when key documents leave the company, we have not enabled prevention or blocking features; we can monitor but not prevent. We also lack network sensors in every office, leaving gaps in coverage. Then there's our network access control (NAC) deployment. We have rolled that out only to large offices -- and not even to all of those -- and we currently monitor only for devices connected to the network. We haven't yet enabled the enforcement of NAC, since we're still tuning the deployment and dealing with exceptions and other challenges related to mobile devices and nonstandard systems.
On the other hand, some of our security technologies are fully mature. Our firewalls have intrusion prevention enabled and actively block malicious traffic. We also enable URL filtering on our firewalls to block access to sites that represent legal or security risks.
But when I step back and evaluate our security landscape, I realize that we're still very much in what Gartner calls the Awareness phase -- in fact, my honest assessment is that we're in the lower quadrant of that phase. My goal for 2013 is to accelerate the security program by enforcing policies, and thereby move us closer to joining that magical 5% of companies that have achieved Operational Excellence. For now, that's a pipe dream, but it's a worthy goal.
This week's journal is written by a real security manager, "Mathias Thurman," whose name and employer have been disguised for obvious reasons. Contact him at mathias_thurman@yahoo.com.
Join in the discussions about security! Computerworld.com/blogs/security
More by Mathias Thurman
- Security Manager's Journal: NAC deployment means better access control at last
- Security Manager's Journal: Plans and processes are made to be revised
- Security Manager's Journal: A little housecleaning
- Security Manager's Journal: R&D's new security lab is a promising step
- Security Manager's Journal: Spam makes a comeback
- Security Manager's Journal: Did DLP tool prevent an assault?
- Security Manager's Journal: When technologies collide
- Security Manager's Journal: Tracking down rogue IT
- Security Manager's Journal: Not-so-innocent email distribution lists
- Security Manager's Journal: A reality check for the department's maturity
Read more about Security in Computerworld's Security Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
Rising salaries boost IT optimism, though not everyone is feeling upbeat. Our survey of 4,000+ IT workers shows who's riding the wave and why. Use our interactive tool and compare your own paycheck. Read more...
