Data Security: Whose Job Is It Really?

Forrester has a recommendation for CISOs struggling with how to secure corporate data: Stop trying so hard.

» View Article

READER FEEDBACK
Preview
J. Avellanet
Wed, 2009-04-08 08:48

This is one of the key points I've advocated for several years in my articles and with my clients when dealing with preventing intellectual property theft by both employees and by contractors.

(You can read a lot more about that and download some articles here: http://www.ceruleanllc.com/Services/Consulting_IPSecurity.htm)

Frankly, requiring the chief security officer, compliance officer or risk officer to be accountable for information flow out of the company is akin to expecting the governor of a state to be accountable for stopping burglaries all over the state; it's just unrealistic. While the office (like the governor) may have ultimate accountability, responsibility for monitoring has to be pushed down to the people who can make the greatest impact at the swiftest level - the supervisors and managers of each functional level (much less the individual employees); again, no different than the mayor, police force (and individual citizens) in a town.

reply
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.