Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

The ABCs of security team building

October 25, 2000 12:00 PM ET

Computerworld - When Tony Ames was hired as an internal auditor for a large West Coast university four months ago, his first order of business was to find out if anyone in the school's information technology department had a clue about information security. So Ames (not his real name, per his request) surveyed the school's 41 technical employees and their bosses so he could determine the baseline security skill set for the department and find out how far he had to go to organize and train an information security team.

Ames told his story to 50 of his peers who recently gathered to hear Michele Guel's full-day training seminar during the SANS Institute's Network Security 2000 conference in Monterey, California.

Guel said she started out six years ago as Cisco Systems Inc.'s only around-the-clock security engineer. She remained the only full-time security engineer for three years and said it almost burned her out.

Things got so bad, Guel said, she started hanging around human resources, checking new employees at the door to see if they had even a hint of security skills or an interest in the subject.

"I talked to interns, students, part-timers, even hobbyists," said Guel. To boost coverage, she said, she began to supplement security support from outside the security department with network administrators who had to pull weekly five-hour shifts on the security watch.

With barely more than 3,000 Certified Information System Security Professionals in the U.S., it's no wonder organizations look within their corporate rank-and-file for even the tiniest seeds of IT security understanding.

Many in Guel's audience said they liked the idea of looking through the organization for people with baseline IT security interests in order to grow a security team, although they questioned the use of itinerant workers for such a critical function.

"Interns are a good source of labor, but most companies don't have the resources Cisco does to do background checks on interns and part-time workers," said one audience member, a network security manager for a technology services vendor on the West Coast, who also asked for anonymity.

    Despite the difficulty in finding qualified people, Guel had a number of suggestion as to what to do once you found your candidates, including the following:

  • Interns with the proper background checks are excellent candidates for operational security projects, including patching, testing, developing and installing security tools.


  • Part-timers and students are best-suited to answer the day-to-day security questions coming from users.


  • Those with management backgrounds may end up evaluating the security impact of major projects.


  • Programmers/developers with security interest may evaluate the use of new Internet technologies.


  • For short-term projects, outside consultants may be a good source of labor, if companies can stomach the $400 per hour average rates for this level of expertise.




Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

Centralized Data Backup and Your WAN
Is your organization prepared to tackle the massive challenge of protecting your data in a cost effective and timely manner? With a growing...  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...  

Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...

The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...  

Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...

Open Source Security Myths Dispelled
(Source: Astaro) Open Source Software is computer software whose source code is available to the general public. This openly viewable nature...  

Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...

Best Practices for Backing Up VMware® with Veritas NetBackup™
VMware® is used by enterprises large and small to increase the efficiency and cost-effectiveness of their IT operations. With this in mind, Symantec...  

Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...