Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

RE: InfoSec Importance

Subject: RE: InfoSec Importance
Date: Fri, 2 Jun 2006 11:06:15 -0700
I am trying to convince my management of the importance of having a
security officer in the enterprise. I have googled the topic, but not
much was found. I would really benefit from your suggestions on how to
approach the management.

  They *may*, just possibly, have convinced themselves that "security is
everybody's job", but the fact is that everyone else is already doing some
other job and so the actual effect is "security is nobody's job".  Unless 
the enterprise is really really small, it needs somebody whose primary
responsibility is security.

  Hopefully, you don't need to just scare them into agreeing that security
is a necessary part of doing business -- they should already be at that 
point.  It's just that there needs to be a person dedicated to making sure
that it happens, a central point of contact between IT, HR, counsel, 
facilities, loss prevention, audit, etc, so that these various efforts 
reinforce each other instead of duplicating efforts or undermining each 
other.

  Experience suggests that there are two common languages which will get
the attention of most managers and executives:  money and jail.  While a
security officer can assist with compliance efforts (stay out of jail),
the main thrust should be on reducing liability and risk.  [Make it clear
that the Security Officer is, first and foremost, a *business* position
and not a *technology* position.  Technical literacy is going to be
important, but it needs to be filtered through an understanding of
business priorities and costs/benefits.]

David Gillett
CISSP CCSE CCNP


<Prev in Thread] Current Thread [Next in Thread>