Six ways to justify security training
Computerworld -
A few days ago, a reader asked if I could help him justify the cost of security training that he and his fellow Unix system administrators felt they needed.
I gave the reader a variety of ideas, one of which is sure to resonate with his manager. When making your pitch, you might want to try these reasons:
1. Avoidance of a costly security incident. The knowledge and skills gained in security training will help system administrators do a better job of securing systems. For instance, host hardening may help to prevent a break-in. Improving password quality may fend off a dictionary attack.
Security incidents are expensive, disruptive and could cause long-term pain for people's careers. Incidents interrupt and take the momentum out of projects and turn department priorities upside down.
2. Avoidance of disruptive downtime. Often, when the knowledge gained in security training is applied to host hardening, those systems have added resiliency. This will make them more resistant to attacks, improving availability.
No one likes downtime, especially unscheduled downtime for security reasons. Unscheduled downtime hurts those end-of-month metrics and other performance indicators.
3. Improved availability. Learning security skills sharpens a system administrator's overall skills: To secure a system, one must be intimately familiar with a system. Administrators trained in security will be more familiar with all of the systems' switches and knobs and will be less likely to make mistakes. Mistakes decrease availability and reliability.
4. Improved consistency. Meticulous system administrators will want to secure not just one system, but all of the systems in his sphere of influence. This will tend to make the configuration of many systems more consistent.
Consistency is a good thing in busy environments where several people are managing a large population of systems. The more consistent the systems are, the less likely things are going to go wrong.
5. Improved failure analysis. Administrators who have received security training will know more about how their systems work. Consequently they'll do a better job of root-cause analysis the next time something goes wrong.
6. Improved audit results. Many companies' IT shops are under more scrutiny than ever. Increased regulation, stricter requirements from customers or suppliers, or the need to reduce the probability of security incidents are driving home the need to improve the security of systems, processes and people.
More companies than ever are facing audits. In many cases, the high-level results of those audits are publicly available (in particular, audits performed on government systems and publicly held companies).
Many companies are having security
Security
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
The State of PCI DSS Compliance at Organizations Today
Download this resource today!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Why Email Must Operate 24/7 and How to Make This Happen
Learn how to avoid an email outage by implementing a hosted email continuity solution.
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
