| | November 2016ENTERPRISE SECURITY8By Jerry Sullivan, CIO and VP, IT, Orlando Utilities Commissions your security department using Mall Cop tactics or a risk-based strategy? For most, I suspect your executive management's perception prevails over the factual answer to this question. For others, behaving like the stereotypical Paul Bart character, played by actor Kevin James in the movie Mall Cop, is the perception that many people have of their Information Security Office (ISO). What is a Mall Cop style of security? It is when the ISO is perceived as a policy enforcer and a roadblock. The ISO promotes rules, checklists, and guidelines that appear to come out of a black box. In other words, many believe the ISO drives IT security because it benefits IT and not the organization as a whole.On the other hand, the risk-based approach uses strategies that take into account not only its requirements, but the needs of the business/enterprise. A key change management tool to implement a risk-based ISO strategy is to make the risks transparent and process-driven. The result is the ISO becomes more of a trusted advisor and partner. The risk-based strategy requires that business requirements and assessments take place to understand the current state and to develop the needs. It assesses the likelihood of an undesirable event with the potential impact of that event. Instead of being a Mall Cop style roadblock, the risk-based ISO is a solution designer and business enabler.Most organizations today use risk management as one of their security tools. At the Orlando Utilities Commission (a municipal electric and water utility serving Orlando and the surrounding areas), our ISO and the information technology department uses risk management as a primary tool. We use risk management to "right size" security to the business and to do our best to deliver the Holy Grail of security officers' everywhere-high "confidentiality, integrity, availability, and accountability."To put risk-based ISO strategy into context, let's first describe the traditional methods. Typical security protocols use policies and guidelines for primary security enforcement and the tools/applications/hardware specified therein to automate security. These guidelines are usually created from a timeframe and situation that is dated as soon as the first new technology and/or malware is developed. The typical response by traditional ISOs is ISafeguarding Organizations through Risk-Based ISO StrategyJerry SullivanIN MY OPINION
<
Page 7 |
Page 9 >