SecTor 2015: Take advantage of changing threat landscape, CISOs told
For example, she said IT security shouldnโt fear cloud computing, which allows organizations to create a pattern of infrastructure, wrap security controls around it and then replicate in a centralized way.
โYour job is not to stand in front of cloud butย to figure out how to enable the organization to rapidly and radically adopt the cloud not just for economics but to improve the overall security posture,โ she said.
Similarly, CISOs need to embrace agile software and business development processes by making sure security teams are advising on risk.
Donโt waste time worrying about millennials who seem to ignore security policies, she said. Instead use them โas an opportunity to radically change the way you approach security.โ For example, divide employees into blocks of users, each with a separate security policy: Privileged users have to use corporately-supplied devices, general users can bring their own.
But arguably her central message is that IT security teams have to create a better brand. โYou donโt want to be โThe House of No.โ You want to be known for innovation. โMy job as a security team is to participate in the creation of innovation with confidenceโ โ Something hokey like that. Define a mission statement. Define yourselves as partners and advisors and sources of dependable and simple information.
โThe reality is business folks want you to be your partner but donโt know how to talk to you.โ
Also, she urged CISOs to talk about risk in business terms to managers and executives. So, for example, let them know there is a risk of forced code compromise in an application that will steal customer information. Or in a medical device that could kill a patient.
Related Download
Sponsor: Acquia
Can we save the open web?
Join the creator of Drupal, Dries Buytaert, in a discussion about the webโs evolution, how we can put the power of the internet back into the hands of the people, and how you can prepare your organization.
Register Now