Project Management Newsletter
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 CIO BlackBerry News and Tips
 CIO Research and Analysis
 CIO Microsoft
 CIO Insider
 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Public Council Teleconference: Application Rationalization — Hidden Costs and Smart Decisions

November 17 at 11:00 am US/Eastern (GMT-5)

Join Honorio Padrón, of The Hackett Group, who will share the drivers for companies to tackle application rationalization and the results of research that define the hidden cost of complexity. Additionally, we will discuss key decision milestones—to start or not, holding the course steady and fulfilling expectations.

Virtual Desktop Cost-Benefit Analysis — Michael Jacobs, Catlin Group

The analysis contained in this presentation measures the cost of everything from the machines and licenses to the infrastructure for virtual vs. traditional desktop environments.

Honor your best senior team members - Apply for the CIO Ones to Watch Award

Get well-earned public recognition for your top up-and-coming team members, your IT organization and your enterprise. Award winners will be announced, publicized and feted in May 2010, great timing to help attract new IT recruits to your company.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 

How to Staff Up for Security

Last year, David Saul, executive vice president and CIO of commercial insurer Zurich North America, pulled a dozen IT staffers ...

 

May 15, 2002CIO

Last year, David Saul, executive vice president and CIO of commercial insurer Zurich North America, pulled a dozen IT staffers away from their daily tasks to combat a virus that was attacking the company’s firewalls. They did a good job limiting the damage, but it took two days?two days in which other work did not get done. Next time, Saul hopes to be ready to respond before a threat surfaces. "We want to be in a safety zone that doesn’t require that kind of immediate mobilization," he says.

That’s why Saul increased his full-time information-security staff from 12 to 18 people, mostly by training, reorganizing and reassigning IT people to security. "Good security equals prevention, detection and reaction," says Saul, who is based in Schaumburg, Ill. "If you’re not going to staff to make the process work, then your exposure to security breaches is higher."

That exposure is an increasingly widespread problem. In a 2001 survey of security practitioners conducted by the Computer Security Institute and the FBI, 85 percent of respondents (primarily from large corporations and government agencies) had detected computer security breaches in the previous year, and 64 percent of those respondents acknowledged suffering financial losses.

In fact, there’s no limit to the damage evildoers can inflict. Sept. 11 proved that. In this environment, many people believe that it’s sheer madness to have an IT staff handling information security on an ad hoc basis. "It’s a hard-and-fast rule, in my opinion," says John Hartmann, vice president of security and corporate services of Cardinal Health, a $47 billion health-services provider in Dublin, Ohio. "If the two roles are shared, business priorities will drive security to a lower priority."

Tim Mitchell, CIO of Sarnoff, an electronic, biomedical and information technologies company in Princeton, N.J., disputes that, saying that his IT staff handles security very well, thank you. But he does agree that people charged with security responsibility must be organized into a team?as his are?carrying out a coherent security program that sets out specific responsibilities and requires regular meetings.

A security team needs to set policies and procedures, assess vulnerability, detect intrusion, respond to incidents and manage security architecture. And perhaps most important of all, it needs a leader.

Finding skilled security professionals to carry out this mission can be tough, and the alternative?training in-house IT staffers who are security novices?can be costly and time-consuming. (Outsourcing security is another option. To read a cautionary tale about the pitfalls of outsourcing security, check out "Exposed," at www.cio.com/printlinks.) But whichever route you choose, here are some ways to enhance your chances of success.

 
 
Loading...
 
WHITE PAPERS

The CIO Calls the Shots

Learn how a selective sourcing model can deliver services in a flexible, efficient manner.
 

Informatica Platform and Integration Competency Centers

Forrester used its total economic impact methodology to interview seven companies that have standardized their data integration practices.
 

Adobe for Business Process Automation

Companies must be able to react to customer demands, competitive threats, and compliance requirements.
 

Increase Customer Satisfaction and Lower TCO

With Adobe® LiveCycle® Enterprise Suite (ES2) software, organizations can easily deploy intuitive user experiences.
 

Top 10 Habits of Highly Effective PMOs

This white paper outlines the top ten habits necessary to make your PMO more effective and maximize its benefit to your organization.
 

Why an Enterprise Project Portfolio Management, EPPM

Beyond traditional project portfolio management, Primavera P6 EPPM improves visibility into every aspect of the project manufacturing process.
 

WEBCASTS

The Case for Data Protection for SMBs

Every business needs a data back-up and recovery strategy. Without it, a severe storm or power outage could result ...
 

Enterprise Capture: Your Onramp to Business Process Automation

Date: Tuesday, December 15, 2009
Time: 11:00 AM PT/2:00 PM ET

Today more than ever companies are see...
 

Enhance SAP

New research from AMR shows that SAP environments can be dramatically more efficient with the addition of document ...
 

Beyond Installing ITPM Software: How a global company reduced risk and successfully implemented ITPM

Live Webcast: November 11, 2009
1:00 PM EST

Hear directly from one of your peers who has reduced risk...
 

The Last Software You'll Ever Buy? The CRM Platform as Development Platform

Join Stan Gibson the principal of Stan Gibson Communications and CDC Software's Scott Munro for an engaging discuss...
 

Real World Performance: More Than Just Benchmarks

Real World Performance: More Than Just Benchmarks
 

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

IDC White Paper: CCM for IT Compliance and Risk Management

Tolly Group Lab Test Results: Cisco vs. ShoreTel

Enterprise Capture: Your Onramp to Business Process Automation

Focus Under Pressure: Why IT Governance Becomes Mission-Critical in a Down Economy

The Total Economic Impact of Network Security Intrusion Prevention

Seven Technologies for Advanced Mail Protection

How Consumerization of IT Will Make Your Business More Productive

Adobe® LiveCycle®solutions for intuitive user experience

Mind the Talent Gap: Global Survey on IT and HR trends and challenges

Seven Ways ITIL Can Help You in an Economic Downturn

See how AT&T can help protect your network.

Top Five CIO Challenges

Streamline IT Costs. Boost Performance with WAN Optimization.

Want to know how you can maximize employee productivity?

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

Increase UPS efficiency without sacrificing protection.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

A Clear View Toward Virtualization

Interactive Q&A helps you discover key ways to maximize IT assets.

Ready to virtualize tier one applications? Check your virtualization maturity.

Think you can't afford a Cisco Switch? Cisco Catalyst Switches are now more affordable.

Five minute business analytics assessment. Immediate results.

Disciplined Autonomy: Resolving the Tension Between Flexibility and Control

Build a Foundation for Unified Communications

Removing the Barriers to IT Governance: How On-Demand Software Changes the Game

Cloud Computing--What is its Potential Value for Your Company?

Seven Design Requirements for Web 2.0 Threat Protection

Learn about the growing threat of insider data theft.

Top to Bottom Performance Management Excellence at the City of Chicago

Architecting Business Intelligence Applications for Change: The Open Solution

Taking the Service Desk to the Next Level

Disciplined Autonomy: Resolving the Tension Between Flexibility and Control

Join us at the US-Brazil IT-BPO Summit, on November 10th in New York.

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion

Read the RSA report: Security for Business Innovation

Webcast: Looking to the Cloud for Email and Collaboration Services

64-page prescriptive guide to security, compliance, and IT operations.

Keep your IT expertise up to date. Join the Intel Premier IT Professionals.

A new fleet of PCs with a total ROI in 10 months. Find your ROI.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

Virtualization Technology as a Business Solution

eZine: A Roadmap to Reducing IT Complexity

World-class trading technology solutions from NYSE Technologies.

If You're Paying for Telecom, You're Paying Too Much. Contact Asentinel Today.

Trade-In your old printer and save up to $1,000 plus free recycling!

infoBOOM! - The Mid-Sized Company CIO's Exclusive Community