Do Security Maturity Models Work?

January 26, 2012
By

Post to Twitter Post to Facebook

Could the addition of a new maturity model to the Nation’s Electrical Grid System improve security and protect the grid from cyber threats? An article at InfosecIsland.com a few weeks ago discussed a recent White House initiative to add a maturity model to be used throughout the entire energy industry.

I’ve always been a bit skeptical of maturity models. Even though this approach could provide small steps for easy incremental security improvements, it could also result in people just finding ways to shortcut the system without actually strengthening anything.

Overall … nice idea for people that really want to improve security … or a shortcut for those just interested in reaching a certain level for contract, marketing, or PR purposes.

via InfosecIsland.com

As part of the Obama Administration’s efforts to enhance the security and reliability of the nation’s electrical grid, U.S. Energy Secretary Steven Chu today announced an initiative to further protect the electrical grid from cyber attacks.

The “Electric Sector Cybersecurity Risk Management Maturity” project, a White House initiative led by the Department of Energy in partnership with the Department of Homeland Security (DHS), will leverage the insight of private industry and public sector experts to build on existing cybersecurity measures and strategies to create a more comprehensive and consistent approach to protecting the nation’s energy delivery system.

“This initiative is another important step forward in improving the security of the Nation’s energy infrastructure and ensuring that the country’s electrical systems remain secure, reliable and resilient,” said Secretary Chu.

“Establishing a comprehensive cybersecurity approach will give utility companies and grid operators another important tool to improve the grid’s ability to respond to cybersecurity risks.”

Continued here.

#####

Please let us know what you think. Will this new maturity model actually mean more security?  Today’s post image is from Rural Community Assistance Corporation.

Post to Twitter Post to Facebook

Related posts:

  1. Will New Monthly “Continuous” Monitoring FISMA Requirements Work?
  2. NIST Needs NICE Notes
  3. Should Cyber Security Focus More on Users?
  4. Best Approach to Increase Cyber Security Professionals
  5. Job: Security Engineer II in Fairfax, VA

Tags: , , , , ,

9 Responses to Do Security Maturity Models Work?

  1. #NOVABLOGGER: Do Security Maturity Models Work? http://t.co/UEF7oVos http://t.co/Inu1SfcI

  2. grecs (@grecs) (@grecs) (@grecs) (@grecs) (@grecs) on January 26, 2012 at 12:52 pm

    BLOGGED: Do Security Maturity Models Work? http://t.co/s3Ktzbea

  3. Cyber Informer (@cybfor) (@cybfor) (@cybfor) on January 26, 2012 at 1:08 pm

    Do #Security #Maturity Models Work?: [nova#infosecportal.com] Could the addition of a new maturity model to the… http://t.co/u9XIvRAv

  4. C-Sec (@csec) (@csec) (@csec) on January 26, 2012 at 1:25 pm

    Do #Security #Maturity Models Work?: [nova#infosecportal.com] Could the addition of a new maturity model to the… http://t.co/eA7GGpMD

  5. #NoVABlogger Do Security Maturity Models Work? http://t.co/QfaQSEgG

  6. #NoVAblogger In Case You Missed It: Do Security Maturity Models Work? http://t.co/QfaQSEgG

  7. Security Maturity Models .. Do these things really work? http://t.co/s3Ktzbea

  8. Security Maturity Models .. Do these things really work? http://t.co/UEF7oVos

  9. Annemarie Zielstra (@a_zielstra) on January 27, 2012 at 1:41 pm

    Good question!: Do Security Maturity Models Work? http://t.co/jAhu2Xwe

Leave a Reply

Your email address will not be published. Required fields are marked *

*

ShmooCon FireTalks Corner

Firetalks LogoMaster Post

CFP

Prizes

More to come...

Search

Grecs's Infosec Ramblings