Security Management
Published on Security Management (http://www.securitymanagement.com)
Security as a Governance Concern
By Peter Piazza



    
Print Edition Only: 
No
Beyond Print?: 
No
Weight: 
0
Teaser: 

Saying that the basis of a good IT security program is effective enterprise security governance smacks of business-school jargon. After all, what exactly is effective enterprise security governance?

Author: 
Peter Piazza

Saying that the basis of a good IT security program is effective enterprise security governance smacks of business-school jargon. After all, what exactly is effective enterprise security governance?

That question is considered in depth by the Software Engineering Institute at Carnegie Mellon University in a new paper that cuts through the jargon to show why this really matters. Their research identified six factors that indicate “an organization is addressing security as a governance concern.”

The first is the company makes sure that C-level leaders understand their responsibilities regarding security; the second is that it treats security as “a cost of doing business,” not a negotiable item that needs regular defending. The third factor is that the company considers security during strategic and operational planning.

Fourth on the list is that the leadership makes sure that managers understand how security serves as a business enabler and how security issues factor into their own job-approval rating.

The fifth element is that security is integrated into enterprise functions and processes, from risk management and hiring to change control. The last factor is recognizing individual responsibilities with respect to the organization’s security.

This paper—which also considers compliance and potential legal liability—is aimed primarily at IT security managers. But physical security professionals will find that the isues addressed are the same as those they face every day.

@   Governing for Enterprise Security is at SM Online.

Related Resources: 
AttachmentSize
governsecurity1005.pdf [1]436.66 KB

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/article/security-governance-concern

Links:
[1] http://www.securitymanagement.com/sites/securitymanagement.com/files/governsecurity1005_0.pdf