Business Intelligence |    Certification |    Cloud Computing |    Community Manager |    CRM/ERP/ETL |    Data Center |    Database |    Enterprise 2.0 |    Enterprise Applications |    Featured stories |    Free Trials |    Green Technology |    Guest Bloggers |    Identity |    Information Technology |    IT Compliance |    IT Decision-making |    Networking |    On-Demand |    Patch Tuesday |    Podcasts |    Programming |    Security |    Social Computing |    Social Media |    Software |    Storage |    Telecommunication |    Videos |    Virtualization |    Windows |    Wireless

Welcome Drazen Drazic, our newest guest blogger. Drazen’s posts will be a feature of our Wednesday coverage of the data security world. Drazen is the CEO of Securus Global. He is a strategic consultant, working across several industries on matters to do with Information Security strategy. Drazen is also a blogger. Heis the chief writer on the IT Security Management site, Beast or Buddha, where this post first appeared.

This is something I have talked about before.

Having been in roles in previous lives that has seen me oversee IT as a whole and IT Security (separate roles), I am of a firm belief that a good CSO has what it takes to be a good CIO, if not a better CIO than most out there. I went from the former to the latter (IT head to CSO) but I believe it can work effectively the other way. It’s not a regular thing though and I haven’t to be honest, seen it happen from memory in recent times – ie; a CSO becoming the CIO.

It’s horses for courses and case by case but more and more, I am seeing competent CSOs out there that have a better picture about IT within their business than the CIO does. Now this will upset some CIOs, but as you know, I don’t mind upsetting those that I think are not up to it. (A recent example here and here). And there’s a heap of CIOs out there, that really are not up to it. Can’t recall figures I have posted before but I’ll throw 80%+ out there as a starter now.

I’ve been working with the CSO of a relatively large business and good global brand in recent times. He’s been on board with his organisation for just over 12 months but in that time, has made some amazing inroads in regards to how this organisation views and works in regards to IT security and risk management overall. But, he’s now hit that time that body builders call the “plateau”, and every little “gain” now takes a mountain of effort – far more effort than gains took in his first 6 months at the organisation. He’s almost ready to move to “greener pastures.”

In his case (unlike many others we see a lot of the time), it’s not that the CIO is being a roadblock intentionally. He’s just maxed out the CIO’s headspace and CIO is struggling to understand what it is that CSO wants to do and why. Fair enough you may say….CSO should be “selling” it better, but at what stage should you cut the “sell” and ask why the CIO as the senior IT person in the organisation just does not get it? You can “sell” it till the cows come home but if someone just doesn’t get it [CIO], when in their role they should, what do you do?

His last resort is a presentation to the CIO (and board) by me. Do I know more than this CSO about his organisation? No, of course not. But external consultants are listened to (for good and bad…it is how it is and we all know that), and maybe having an external party being able to present a broader view of what “others” out there in business are doing, can kick start more gains by the CSO in his organisation. Time will tell but I digress from the topic.

qualysads

In my view, having spent a good deal of time in this organisation and getting to know the organisation, key stakeholders, their business strategy etc etc, it’s clear to me that CSO has a far stronger knowledge of all of this vs. the CIO.

It’s not because this person [the CSO] is just good at what he does. He is, but a good CSO should know their organisation back to front to be able to be a good CSO and develop a good IT security and risk management program and strategy.

Combined with good business knowledge, you have someone [the CSO] who has that holistic enterprise view – better than most CIOs. What else do they need? Serious question. (See previous links on CIO failures above and ask this question again).

Related posts:
Risk Management – Various Posts
The 7 Reasons why Business are Insecure
Risk Management – Great in meetings, not so much in practice

Tags: , ,



Share
                                                 
sharebar end


This entry was posted on Wednesday, July 15th, 2009 at 8:26 AM and is filed under Community Manager, Guest Bloggers, Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.


Comments



Leave a Reply
 

You must be logged in to post a comment.

 



 
Related Tweets




Syndicated Content
  Our New Offices...
Our offices recently underwent a redesign of its own. Here are some photos of our new digs....

How To Find Your Next Job Using Social Media
I'm attending the next WebGuild Event on an interesting topic about yet another means for tapping into your social network: How To Find Your Next Job Using Social Media. The event is on Tuesday, August 17, 2010 from 6-9:00 PM...

POLL: Treatment of Link Tips Versus Standard Links
We've been working on better differentiating on our site standard hyperlinks from link tips which render a popup callout bubble. What's your vote? QUESTION 1: Option 1: Do you prefer the 'help' cursor onmouseover for link tips? Option 2: Or...

  PayPal UK Launch Security Key - Guest Posting from PayPal
I am happy to say they are using VeriSign Identity Protection to deliver this, which means that PayPal Customers will be able to use their token at other sites who join the VIP network. PayPal are the first UK members of the network, but there are around 30 other members in different countries around the world so you can expect to see more places where you can use your token in the UK appearing shortly.

Facebook scam - Part 2
This just in from the BBC web site, Symantec have identified a virus that steals user names and passwords, nothing new there. But, if I understand this right, it is delivered through a Facebook invitation from someone you don't know and delivers malware which can then steal user names / passwords and also keylog credit card info.

Survey finds passwords are not secure - well d'uh!
I don't think the vendor community has been crying wolf about the problems that stronger authentication solves, more like highlighting that this problem is here and growing. Well the discussion I have had recently with many different organisations across many different industries are now resulting in more and more consumer projects in this area

  Cloud Identity, Trust and the Liability Elephant.
I have been involved with a couple similar initiatives around certification for identity and thought it would be interesting to explain the logic behind these efforts. The first initiative is led by the Open Identity Exchange and is based on...

Greek Heroes, Facebook and Trust
When Achilles was a baby, the oracle predicted that he would die in battle from an arrow. Thetis, Achilles' mother who did not want her son to die decided to dip Achilles' body into the water of a river that...

PCI for the Cloud
For most enterprise and security vendors, the cloud is fascinating both as a technology and a business disruptor. In fact, SAAS CEOs such as Successfactor, SalesForce and NetSuite are hot shots in Silicon Valley these days. Yet, most of us...

Search
 Whitepaper   Webcasts  Videos  All

     


Member Login
User Name  :    Password  : 

Register | Forgot Password

Featured blog

Favorites

Sponsors
        

Sign up to receive email notifications about our newest white papers
.........................................................................
           Full Name  : 
Email Addresss  : 
   Confirm Email  : 


Breaking News
 
Featured stories