Chief information security officers: Good news and bad news

By Jon Oltsik, CNET News.com
Tuesday, September 25, 2007 12:04 PM

According to ESG Research, 77 percent of large organizations ( 1,000 or more employees) employ a chief information security officer (CISO), up from 63 percent in 2005. ESG also found that more companies also hired chief compliance officers, chief privacy officers and chief risk officers in this two-year period as well.

This data demonstrates that CEOs and board members are willing to throw money and talent at creating real operations around security, compliance, governance and IT risk.

Do these numbers mean that CISOs are becoming more strategic? I wouldn't go that far just yet--here's why. I recently had lunch with a very seasoned security professional who has held the CISO title several times and is currently looking for his next position. My friend told me about employment discussions he has had with several well-known companies. One multibillion dollar firm had the CISO position four levels down from the CIO. At another company, the most senior security professional was a senior director. My friend also described a situation where the VP of networking with little actual security experience was given the CISO title. In spite of his stellar resume, this firm wanted to bring him in as a direct report to its new and inexperienced security executive.

So, the good news is that companies are actually hiring security executives but the bad news is that many still consider them glorified firewall administrators buried in the organization. How will this mismatch help to actually improve security?

Lots of people realize they need to lose weight so they join health clubs and never actually workout. Think of the CISO as the organizational equivalent of the health club here.

I'm often quoted as saying that information security is far worse than people think--this is one example of why I believe this to be true. If the organizations that collect our taxes, treat our illnesses, invest our money, and sell us goods/services consider information security as a low-level necessary evil, we are all in big trouble.

This article was originally a blog post on News.com.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Time to map out

Blog thumbnail

Before anything else, let me devote a few words to the fallen journalists and other victims of the brutal massacre that occurred last week in the southern province of Maguindanao...... by Melvin G. Calimag

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web