Groups: Cybersecurity Needs to Move Beyond an IT Issue

By Grant Gross
Mon, October 20, 2008

IDG News Service —

Many businesses need to expand the number of in-house departments that focus on cybersecurity beyond IT, with an interdisciplinary group led by the chief financial officer dedicated to assessing and reducing cyberrisk, according to a new report released Monday.

While the IT department should remain a major player in cybersecurity efforts, the CFO and the legal, risk management, human resources, public relations and other departments need to be involved in decisions about risk before cybersecurity breaches happen, the report said. It was released by the Internet Security Alliance (ISA) and the American National Standards Institute (ANSI), a nonprofit group focused on setting standards for U.S. industries.

The two trade groups released the report, "The Financial Impact of Cyber Risk," through a series of workshops in which more than 30 organizations participated. Participants represented the perspectives of several corporate departments, and among the organizations involved were IBM, Lockheed Martin, Crimson Security, State Farm Insurance, Carnegie Mellon University's Software Engineering Institute, and the U.S. Departments of Justice, Commerce and Homeland Security.

"The lesson that this workshop learned quickly was that cybersecurity, which has been traditionally viewed by some companies as an IT issue, is not just an IT issue," said Ty Sagalow, president of product development for general insurance at American International Group (AIG) and the workshop leader. "Just like it is not just a legal issue to be solved by the general counsel. Just like it is not just a reputation issue or a communications issue to be solved by the head of public relations."

The report, subtitled "50 Questions Every CFO Should Ask," recommends that business CFOs become heavily involved in focusing on cyberrisk if they aren't already. CFOs are in a position to see the big picture and budget for increased IT spending, if needed, or cybersecurity insurance or more resources in other departments, Sagalow said. In addition, CFOs need to understand the potential financial risks to breaches or leaks, he said.

Asked if some CIOs or IT department heads would see increased involvement from CFOs and other departments as encroaching on their turf, members of the task force that produced the report said they shouldn't. Many IT departments already recognize that they're only part of the solution to cybersecurity issues, said Edward Stull, a software architect for Direct Computer Resources and chairman of an IT security best practices group for the InterNational Committee on Information Technology Standards.

Many IT departments are underfunded, added Larry Clinton, ISA's president. Increased attention from the CFO could result in additional funding and an additional focus on IT needs, he said.

Continue Reading

Learn how your answer to this question compares to your peers by taking this quick poll. See how your peers are dealing with the challenge of ensuring a highly capable server infrastructure as technological shifts impact the application server platform.
With increasing data growth, comes increased need for data security.  The existing DLP model, with a focus on compliance/enforcement is not sufficient as the data discovery and classification capabilities are not granular enough.  Read this paper to find how you can efficiently and accurately manage your risk by rapidly inventorying and classifying your data and then developing remediation workflows that support business needs. 
This paper breaks down attack sources into four categories: external, malicious insiders, accidental insiders, and unknown.
The rapid growth of data and technology is creating challenges for organizations as this digital data is considered to be business communications and must be preserved according the same industry-specific regulations governing the retention and discovery of emails and more traditional forms of electronic communications. This paper examines the role that Data Loss Prevention ("DLP") technology can play in helping organizations address the challenges of locating information in response to electronic discovery.
This research, conducted by the Ponemon Institute, focuses on issues relating to the use of data protection solutions such as endpoint encryption and data loss prevention within the workplace.
This report, by Jon Oltsik from Enterprise Strategy Group, examines the need for a new business-centric approach to DLP in order to align business and security requirements.
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
VMware recently announced VMware vFabric™ Data Director, a new database deployment and operations platform that enables enterprise IT organizations to offer database as a private cloud service. Built on top of VMware vSphere 5, vFabric Data Director enables IT organizations to ontrol database sprawl through automation and consistent policy enforcement and accelerate application development cycles with self-service database management. Attend this webcast to learn how vFabric Data Director can help you build database-as-a-service in your datacenter.
A simple, cost-effective disaster-recovery solution for virtual environments is high on the agenda for IT organizations as they virtualize more business-critical applications with VMware. VMware vCenter™ Site Recovery Manager-the market-leading disaster-recovery product-ensures the simplest and most reliable disaster protection for all virtualized applications. VMware vCenter Site Recovery Manager provides centralized management of recovery plans, enables nondisruptive testing and automates site-failover processes.
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to expand disaster protection beyond their most critical applications, largely because they are uncertain whether the quality of the protection is really worth its cost. VMware vCenter™ Site Recovery Manager 5 is the market-leading disaster recovery product that addresses this situation for organizations of all kinds. It complements VMware vSphere to ensure the simplest and most reliable disaster protection for all virtualized applications.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center