Latest Comments
"Excellent info. If you use Gumtree Australia you will see many obvious scam posts in all ..."
by Marian Imrie | Dec 5, 2008 4:45 PM
 
"Very nice and useful information. UT4B4. Tape4backup.com"
by Lto-4 Tape | Dec 4, 2008 9:23 PM
 
"Interesting that you do not bother to list the one AV that has consistently passed the VB100. ..."
by Ben | Dec 4, 2008 6:00 PM
 
"I like this"
by nanwin | Dec 3, 2008 3:05 PM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM

McAfee CSO: Security pros need to better understand business needs

  • Email a Friend
  • Print Page
By Negar Salek
Mar 14, 2008 4:14 PM
Tags: McAfee | CSO: | Security | professionals | need | to | better | understand | business
His advice to fellow security professionals about how best they can achieve their goals and needs when dealing with business was a highlight.

“When dealing with business, security professionals are faced with two questions: what do I get and what does it cost? Until the [security professional] is really able to address those two questions we are going to be in a place that’s difficult for us,” said Carmichael.

“After you put a firewall most businesses ask what does that mean; after you put in a single sign on they ask what does that mean; and after you become compliant again they ask what does that mean and how did you help business?”

The inability for IT and business to adequately communicate and understand each other’s needs is an ongoing issue facing the industry, however in this case Carmichael insists change should be in the hands of the security professionals.

“Security offers so much to business,” said Carmichael. Businesses make risk choices every day, we help business reduce risk. [However] business understands intuitively the value of security and yet you’ll find most security staff don’t have a good business relationship.”

It’s not because securitisation isn’t providing incredible value, because it does. The issue is that they are not providing the right messaging when they communicate their success and effectiveness, he explained.

A prolonged focus on the dark-side of security is also a cause for concern. “Ninety percent of presentations in security start with, the world is not a good place; bad things are going to happen; you’re going to lose your money; you’re going to lose your identity, as well as your corporate reputation.”

If you take a look at that methodology it is not a positive solution space, he said. “We have to get beyond that and change our processes and methodology and our underlying philosophy to succeed. If we continue in the path that we’re in we’re going to be adversarial with business.”

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Risk Management Whitepapers