The Macrosite for News, Analysis and Opinion about the Future of the Internet
DISCUSS   PRINT     Email This

Chief of Security

6/12/2012 13 comments
no ratings


With password breaches mounting, do all enterprises need a C-level security honcho?
  Yes
  No
  I have no idea

DISCUSS   PRINT     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 2   Next >
HIthinkTank
Rank: Cave Painter
Tuesday June 26, 2012 5:04:39 PM
no ratings

Rather than belabour the PW issue, there are certainly far better ways (including more secure and efficient) for securing corporate enterprises all the way down to permitting private visitors access to your data.  What part of utilizing existing technology doesn't make sense to implimentation of a higher level of metrics to security?  Certainly MS itself has danced around the biometrics security issue with capabilities of fingerprint readers (see their own post issue regarding changing the same @ http://support.microsoft.com/kb/899626) among other readers, so why not solve the issue by driving hardware and software in that direction once and for all?

In fact even homeland security is a good resource for the encouragement of biometric ID as well as USCIS (http://www.uscis.gov/portal/site/uscis/menuitem.5af9bb95919f35e66f614176543f6d1a/?vgnextchannel=9059d9808bcbd010VgnVCM100000d1f1d6a1RCRD&vgnextoid=b3be194d3e88d010VgnVCM10000048f3d6a1RCRD). 

Considering the vunerability of data both from inadvertant theft (lazy or ineffective regular password modification) through ignorance up to corporate espionage (poor corporate security implimentation) wouldn't the addition of a hardware and software security implementation be worth it?  Consider the potential cost to a corporations, it's data loss and proprietary technology!  Using biometrics provides for the relatively easy identification of all log ons and the user unique identity.  All legitimate users shouldn't consider this to be any kind of invasion of privacy, if in fact the person wants to express themself honestly and be a legitimate data accesser, wouldn't you agree?  I only can see that there would be a problem with those who would not want to be forthright in identifying themselves anyhow if their intent was to be dishonest!

 

scucci
IQ Crew
Tuesday June 26, 2012 9:55:54 AM
no ratings

Either way there needs to be a person that is responsible for information security in general and only focuses on this effort all day long. The CIO is not able to do this since he's being pulled in every direction all day long.

If its an SVP or CISO it really doesn't matter to me. I've seen people in the past that were SVPs that had the title of CISO, so the title doesn't really matter as long as they have the power to get things done and bring information security, not just network security, to the board level.

Paul Whyte
Researcher
Saturday June 23, 2012 5:50:53 AM
no ratings

Hi David,

I completely agree with your second paragraph. WE can make the argument all day long about strong passwords and training of employees but if there aree gaps in our IT systems, then such efforts won't take us anywhere. Your closing thought in that second paragraph is very spot on. How many times do we think of issues like password security at the very onset of developing an IT system? As is often said, security is always an after thought and as a result therefore, we are always chasing shadows trying to fill the gaps left by such a systems' mindset.

davidmanheim
IQ Crew
Thursday June 21, 2012 10:42:21 AM
no ratings

@nathanwsonack: Agree!

If there is accountability across the board, you don't need a new person to step in to check about security. If there isn't accountability, a new C-level exec would have little influence - or too much. But it's convenient to think you can fix this without systemic change.

Good security decisions start with good IT decisions. Requiring great passwords isn't a good solution, since users have every motivation to make it easy for themselves. Requiring training is no panacea, since most trainings are useless - and a waste of time. What is needed is the mindset that systems must be built to standards that make security and resiliency priorities.

Companies need to focus on building things for the long term to do this, and not to appoint a new officer to take the blame when it fails. The existing C-level execs need make a culture where short term decisions that sacrifice long term priorities for convenience or hitting deadlines into a career killer. That's true for reputation, for security, for resilience, or to be clearer: for anything that matters to CEOs except short term profits. And this means they need to make a choice; invest and prevent these failures, or increase their risk. If only I didn't know what many CEOs will do when faced with this choice - take a bigger paycheck for last quarter's profits, and make sure a scapegoat is in place.

Mary Jander
Thinkernetter
Wednesday June 20, 2012 5:37:24 PM
no ratings

Given security converns, it's ironic to see the cry for more executive accountability, not for the elimination of bosses -- which some have embraced as the best corporate wisdom.

nathanwosnack
IQ Crew
Monday June 18, 2012 3:44:29 AM
no ratings

C-Level Security Honcho, no. A CTO, CSO, and CIO that implement proper security based on standarized and updated policies? Yes.

Kim Davis
Thinkernetter
Wednesday June 13, 2012 4:29:44 PM
no ratings

I think the first question is whether the role is restricted to IT security.  If not, why the CIO?

Nicole Ferraro
IQ Crew
Wednesday June 13, 2012 2:01:14 PM
no ratings

Joe: Why to the CFO rather than the CEO? Or even the CIO?

Joe Stanganelli
Thinkernetter
Tuesday June 12, 2012 4:51:18 PM
no ratings

And then you make a C-suiter in charge of security...and then who answers to whom?

Just make an EVP or SEVP in charge of security (both physical and network), answerable to the CFO.  Leave it at that.

Kim Davis
Thinkernetter
Tuesday June 12, 2012 4:39:20 PM
no ratings

Many organizations have a CIO, and a Chief Security Officer - a post which long predates major concerns about digital security.  We must always remember that security does not begin and end with networks.  It's also all about locks on doors, for example.

What is needed in those cases is a clear understanding of who is accountable for what.

Page 1 of 2   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
a moderated blogosphere of internet experts
Jason Mick
Jason Mick   6/19/2013   7 comments
The US National Security Agency learned the hard way that it can be dangerous to give a contractor too much money and access, with too little scrutiny. The NSA and other government agencies hire tens of thousands of contractors a year to analyze data. Edward Snowden -- who revealed himself as the NSA leaker after fleeing the country -- was one such contractor, reportedly holding a $122,000 salaried position at Booz Allen Hamilton at the time of his departure.
Charlotte Erdmann
Midsize businesses rarely achieve the same standards of security in their own datacenters as professional providers that specialize in delivering these services to organizations.
IETV: the thinkerNet on film
5
of
John Kennedy
How Big-Data Is Changing Marketing

6|13|13   |   1:07   |   1 comment


Big-data and analytics tools enable marketers to understand customers as individuals, identifying unmet needs and addressing each customer as a "segment of one," says John Kennedy, VP corporate marketing, IBM.
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   10 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   1 comment


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
2pm EDT
Fri
Jun 21st
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   6/18/2013   Post a comment
The IBM Smarter Commerce Global Summit in Monaco kicked into high gear today, and we've already begun to see news emerging from that lovely city-state by the sea.
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
NSA Leaks Shine Spotlight on Perils of Contractor Partnerships
Jason Mick
The US National Security Agency learned the
hard way that it can be dangerous to give a contractor too much money and access, with too little scrutiny. The NSA and other government agencies hire tens of thousands of contractors a year to analyze data. Edward Snowden -- who revealed himself as the NSA leaker after fleeing the country -- was one such contractor, reportedly holding a $122,000 salaried position at Booz Allen Hamilton at the time of his departure.

CLICK FOR MORE