How to Design a Security Strategy (and Why You Must)

Approaching senior executives and the board with a sound business plan and project roadmap for security significantly increases the odds of getting funding—and eliminating the frustration that comes with allocating money to ad hoc security efforts and achieving the predictable, lackluster results.

By Gary Loveland, PricewaterhouseCoopers
Thu, February 26, 2009

CIO — We often hear from CIOs who are frustrated by the amount of money they allocate to security projects and technology,compared to the results they achieve. In some cases, executives perceive that security seems to worsen even as spending increases. The reasons vary, but the root cause usually is the same: the lack of a well designed, enterprise-wide security strategy.

Most organizations take a reactive approach to security, implementing point solutions in response to security threats or breaches. Such an approach is costly, and it results in a patchwork of solutions that paradoxically make the organization less secure.

What's needed is a comprehensive security strategy that clearly defines the current state of the security environment and aligns with business objectives for the next three years. Without it, the CIO won't be able to elevate security to the level of corporate strategy—where it belongs.

The first step in designing a security strategy is to understand the current state of the security environment. That may seem obvious, but many companies skip this critical step.

The "spider diagram" (Figure 1) shows the eight security functional areas (SFAs) that make up the security environment of an organization. To evaluate the current state of the environment, organizations must rate the level of security in each area, on a scale of 1 (manual processes, not integrated) to 5 (integrated, automated, optimized processes). This exercise will reveal the organization's security gaps and identify which are most critical. Focusing on these eight areas will enable the organization to address security proactively—the only way to gain control.

Figure 1: Current state of security <br />Company Performance

Many organizations approach security as a technical problem, installing firewalls, antivirus software, and other technology to defend against external threats. But research by PricewaterhouseCoopers (Global State of Information Security Survey 2008), in collaboration with CIO Magazine and CSO Magazine, and studies by others suggest that it's the insiders—the employees who have ready access to systems and sensitive information—who are responsible for the bulk of security problems. If employees are careless with customer data, share passwords or take home laptops filled with credit card numbers, the best technology in the world won't keep the organization secure.

This helps to explain why, despite spending millions of dollars on technology, many companies fail to create a secure environment. In focusing on technology, they neglect the people and processes that make the technology work—or render it irrelevant.

So education and awareness is a critical SFA, and in my experience, it's where organizations struggle the most. Too often companies fail to implement the security processes and training required to ensure that employees (especially employees outside the IT department) understand what they must do to keep the organization secure. Educating employees is effective, and it costs relatively little compared to the price tag for technology solutions (not to mention the fines and brand damage that result from security breaches).

Another area in which companies often fall short is security management. PwC research on the state of information security indicates that one of the key predictors of fewer breaches and less downtime is having security management at a senior level, usually a CISO or CSO. (The other key predictor is having a documented security strategy in place.) In organizations with major security problems, you'll often find a CSO who is accountable for security but may not have the necessary level of authority and/or responsibility to require employees to take the steps needed to maintain a secure workplace, such as changing their passwords each month.

By contrast, in companies with strong security environments, the CSO or other security officer has responsibility and authority for ensuring security, and the backing of a steering committee to enforce compliance with security rules. We recommend that this committee include the CIO, auditors, the leaders of all business units, and senior managers from IT, compliance, risk management, and other key functional areas, such as marketing and finance.

The steering committee should be involved in developing the security strategy as well as providing oversight, and it should help to foster education and awareness of security processes. The committee also can keep an eye on the "big picture" of security initiatives throughout the organization, and identify ways to streamline security efforts.

For instance, we have seen some clients approach SOX, HIPAA and PCI remediation as individual projects, even though the security requirements of the standards are largely the same. Integrating similar compliance processes can produce quick wins for an organization, in terms of enhanced security, reduced costs and increased efficiency.

Figure 2: Desired future state of security <br />Company Performance

Continue Reading

What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
The promise of enterprise mobility means that employees are more productive and address business issues in a timely, untethered manner.
Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.
Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
PCI DSS is mandatory for any business that handles confidential cardholder data. Riverbed® Stingray™ Traffic Manager and Stingray Application Firewall Module help with many parts of the PCI DSS specification, notably the web application firewall (WAF) requirements of section 6.6.
PCI DSS is mandatory for any business that handles confidential cardholder data. Riverbed® Stingray™ Traffic Manager and Stingray Application Firewall Module help with many parts of the PCI DSS specification, notably the web application firewall (WAF) requirements of section 6.6.
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents indicated they were not confident that their organization would be able to detect the loss or theft of sensitive personal information in their company's databases and applications.

Join featured guest Dr. Larry Ponemon from the Ponemon Institute, to discuss these new findings and how to best address the growing number of data breaches and privacy challenges that are facing your organization. This webinar will focus on:

- Understanding the current state of privacy and data protection in the production environment
- Identifying areas of greatest vulnerability
- Keeping data secure without sacrificing productivity
- Enterprise and configurable solutions for multiple applications
Learn how IT teams can protect against spear phishing tactics. Harry Sverdlove, chief technology officer of Bit9 offers a frank discussion about spear phishing - the most common technique used in today's advanced attacks. Learn how spear phishing works and three recommendations for IT to protect against modern threats.
Download this eSeminar to hear from experts Ziff Davis Enterprise, VMware and HP and learn how client-side virtualization can improve your organization's performance, while reducing the IT burden of managing and maintaining an increasingly diverse client universe.
In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for standard users.
More companies are adopting business service management practices to better align their business and IT needs. Download this video to hear findings from the 2011 BSM Maturity Benchmark Survey to learn how companies are taking a customer-centric approach to IT management.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links

Master the cloud with the power of convergence from HP

Connect with IT leaders redefining mobility at the Enterprise Mobile Hub

Choose New and manage one device instead of 170

Choose New for 8x the firewall and NAT performance

Check out a smart way of mobilizing your business with enterprise-ready Samsung Mobile.

Redefine your data center with HP servers.

Enhance your business with Windstream IT Solutions. Speak to someone local.

BlackBerry® Mobile Fusion. Different mobile devices. One platform.

Click to see how Accenture has delivered high performance to clients

CYBERMARYLAND | Learn Why Maryland is the Epicenter for Cybersecurity

Get Ethernet speeds from 1 Mbps to 10 Gbps - Comcast Business Class

Cognizant. Leading in Business, Application & Technology Services

Collaboration: driving better business outcomes

Gain cutting-edge insights at MIT in 2-5 day executive programs.

Complimentary Gartner Report on BYOD: Media Tablets & Beyond. View Now

Elevate storage agility and efficiency with HP 3PAR storage.

Choose New and slash the number of devices you manage

Customized information views & Twitter events at New Fulcrum Point

Splunk translates machine data into "aha" moments for IT and the business.

ManageEngine Desktop Central - Automate and Audit Your Desktop Management! Learn More...

Cloud Readiness Starts with Intel® Technology

High performance. Delivered. Click to see Accenture's client successes

Visit the Virtually There Learning Page to learn how to use virtualization to your competitive advantage.

Free: Hunter Muller's "The Transformational CIO."

Join us for an upcoming Microsoft 365 live online demo event.

Discover your easiest path to unified communications

Virtualizing Your Infrastructure Just Got Easier

Connect with global CIOs now at Enterprise CIO Forum

Resource Center