5 Tips for Managing Security in a Recession

As company purse strings continue to tighten in a tough economy, can security afford to manage risk and even be a business driver? Art Coviello, President of RSA, gives CSOs some tips.

» View Article

READER FEEDBACK
Preview
Audry Agle
Thu, 2009-03-19 15:52

Having developed Security Awareness programs with the mantra that "security is everyone's responsibility", I especially appreciate the focus of this article on sharing the processes and costs among the enterprise. It's difficult to get the organization to accept responsibility for security when the prevaling attitude is that IT will take care of it all through technical controls. If there are existing operational processes in place that can be leveraged to aid in security - it's only common sense to use them. Something like a helpdesk ticketing system, for example, can be deployed organizationally to aid in security oversight functions with little additional cost. This can help reinforce the concept that while InfoSec governance may be handled through a particular group, ownership belongs to everyone.

reply
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.