May-June 2017ENTERPRISE SECURITY| | 9 | | November 20159CIOs, CISOs, and corporate leaders face the complex task of understanding every system, computer, and connection point, and then knowing what each one is supposed to be doing in a networkinfrastructures all provide a virtual open door to a determined foe. In OPM's case, the threat that caused the data breach could have been injected well before Archuleta was even considered to lead the agency and lay dormant until the adversary decided to activate it. It is further compounded by the need to have a very open network to ensure the broadest access to the agency by the public they serve. Complex and ConstrainedCIOs, CISOs, and corporate leaders face the complex task of understanding every system, computer, and connection point, and then knowing what each one is supposed to be doing in a network. This knowledge must occur in a new normal that includes sensors that regularly spew out huge volumes of false positive data. Coupled with declining budgets, this creates a perfect storm of complexity and challenges. The complexity of corporate networks that often merges new systems with legacy applications present additional challenges to CIOs and CISOs who are trying to secure their enterprises. It is no longer sufficient for large corporations or government entities to put up firewalls, run anti-virus protection, and keep systems patched. Security professionals must also be true experts in all aspects of the corporate network, connections, systems, interfaces, data stores, where key information is stored, what and where backups are held, and where the company should communicate and where it should not. The need to connect people globally via networks, in a fluid and seamless manner 24/7 with no outages or interruptions, further complicates the problem. Restricting users, increasing security steps, and adding more procedures run counter to efficiently connecting the business. Talent ChallengeOne of the biggest issues CIOs face is find-ing talented people who can understand the entire network and make smart deci-sions when a threat is detected. Attain-ing the needed level of awareness takes time, talent and dedication by a highly integrated security team that is capable of synchronizing in-ternal and external threat information, translating those sources into the environments they are attempting to secure in actionable ways. This is all happening within a very competitive market, where much of the best talent is being scooped up to work in soft-ware startups and development houses and in the end is not practicing security of institutions, systems, and networks.A Call for LeadershipAfter seeing what happened to Katherine, as well as executives at Target, Sony and other companies after a data breach occurred, I fear the current environment will have a terrible impact on the future of the cyber-security profession. Talented people who are dedicated and committed to security operations do not want to have their work and efforts maligned in the public eye. Within the government, there are individuals who are working very hard every day to secure these data environments. I know them to be highly dedicated and committed professionals striving to do their very best despite facing a very challenging threat as well as a financially constrained environment. If the trend continues where we publicly attack the best efforts and intentions of our people, it will become even harder to hire and keep cyber-security professionals willing to do this essential job. I believe the role of leadership in an organization is to provide support to these leaders and their teams by creating an environment where they can thrive and ultimately master their craft in a non-threatening, growth-oriented environment.In many cases, their skills are unique and they are doing jobs that most people are unable to do to keep the rest of us safe. They have my highest respect for their dedication and service to the nation and we must strive to ensure they continue to be valued. ESBob Fecteau
<
Page 8 |
Page 10 >