| | DECEMBER 2022ENTERPRISE SECURITY8IN MY OPINIONIN MY OPINIONAs the C-level IT executive for multiple public and private sector organizations, I've oftentimes found myself playing referee and chief mediator between our IT infrastructure and information security teams. The tension of balancing the shifting requirements of physical and logical security against evolving, tactical infrastructure needs and the burning desire to innovate is a struggle that many IT leaders wrestle with daily.While serving in the capacity of Chief Information Officer (CIO), the IT Security leader reported directly to me in multiple organizations, but I've also exchanged notes with other colleagues who worked closely with a Chief Information Security Officer (CISO) as an organizational peer. This can occasionally lead to conflicts if goals, approaches, and objectives are not properly communicated, agreed upon, and aligned.This is further complicated by rapidly evolving state and federal legislation which addresses the handling of personally identifiable information (PII) and organizations' ability to protect this data. In many cases this forces organizations with limited resources to become Federal Information Processing Standards (FIPS) 199 & 200, Federal Information Security Management Act (FISMA) and National Institute of Standards and Technology (NIST) 800-37 and 53 complaint, which requires a significant effort in cases where there are limited protections in place at the application, database levels, and infrastructure levels, forcing IT leaders to quickly scramble into action to remediate potential vulnerabilities. The past few years have born witness to highly publicized data breaches, ransomware attacks, and system intrusion, leading to a loss of credibility and revenue in most cases. This oftentimes leads to a frenzied response from the IT team to lock down systems and prevent further intrusion, while putting controls in place that further restrict functionality and employees' ability to access organization resources externally. In response to the burgeoning threats, legislators have scrambled to put laws in place that sufficiently address the threats. One noteworthy example of relevant statements is a recent piece of legislation reads:"For organizations to remain secure,the CIO and CISO must work together to implement controls, maintain current patch levels, and monitor systems to ensure that vulnerabilities are prevented, detected and mitigated as quickly as possible."More language that outlines the intersection between IT Security and Infrastructure comes directly from FIPS Publication 200:"The minimum-security requirements cover seventeen security-related areas with regard to protecting the confidentiality, integrity, and availability of federal information systems and the information processed, stored, and transmitted by those systems. The security-related areas include: (i) access control; (ii) awareness and training; (iii) audit and accountability; (iv) certification, accreditation, and NEGOTIATING THE CONFLICTS BETWEEN CYBER RISK MANAGEMENT AND IT INFRASTRUCTURE By Vennard Wright, Chief Information Officer, Washington Suburban Sanitary CommissionVennard Wright
<
Page 7 |
Page 9 >