<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaInfosecPortal.com &#187; ciso</title>
	<atom:link href="http://www.novainfosecportal.com/tag/ciso/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &#38; resources for infosec professionals in NoVA, DC, &#38; MD</description>
	<lastBuildDate>Fri, 03 Feb 2012 17:30:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>What! No CI(S)O*?</title>
		<link>http://www.novainfosecportal.com/2009/09/09/what-no-ciso/</link>
		<comments>http://www.novainfosecportal.com/2009/09/09/what-no-ciso/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 15:00:24 +0000</pubDate>
		<dc:creator>paques</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[cfo]]></category>
		<category><![CDATA[ciso]]></category>
		<category><![CDATA[cto]]></category>
		<category><![CDATA[guest-poster]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[novainfosec twits]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security-news]]></category>
		<category><![CDATA[wade-woolwine]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=2104</guid>
		<description><![CDATA[Written by Guest Poster Wade Woolwine The Chief Information (Security) Officer* is a top level executive who is responsible for defining and executing a plan for identifying, cataloging, and protecting information assets throughout a company or government agency. Seems like a pretty important job, right? So why is it that so many public and private companies don&#8217;t have one? Sure, there might be a CTO, or legal team who claims that part of their mission within the company is data, but that simply isn&#8217;t enough. In today&#8217;s world, just about every industry must maintain a certain amount of personal information about their customers even if the soul purpose is to be able to reliably discern one customer from another. In more extreme cases such as social networks, paid services providers, banks, or healthcare providers, the amount of PII (personally identifiable information) amassed in information systems becomes a huge liability for the company and consumers demand that this information be kept safe from criminals. Who bares the responsibility for this data? The CEO? Probably not, most CEOs are concerned with company performance, products, and marketing &#8211; in other words, making money for the company or share holders. How about the CTO? [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=What%21+No+CI%28S%29O%2A%3F+http%3A%2F%2Fj.mp%2FnJJgDf" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/09/09/what-no-ciso/&amp;t=What%21+No+CI%28S%29O%2A%3F" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><em>Written by Guest Poster <a href="http://www.wadewoolwine.com/">Wade Woolwine</a></em></p>
<p>The Chief Information (Security) Officer* is a top level executive who is responsible for defining and executing a plan for identifying, cataloging, and protecting information assets throughout a company or government agency. Seems like a pretty important job, right? So why is it that so many public and private companies don&#8217;t have one? Sure, there might be a CTO, or legal team who claims that part of their mission within the company is data, but that simply isn&#8217;t enough.</p>
<p>In today&#8217;s world, just about every industry must maintain a certain amount of personal information about their customers even if the soul purpose is to be able to reliably discern one customer from another. In more extreme cases such as social networks, paid services providers, banks, or healthcare providers, the amount of PII (personally identifiable information) amassed in information systems becomes a huge liability for the company and consumers demand that this information be kept safe from criminals. Who bares the responsibility for this data? The CEO? Probably not, most CEOs are concerned with company performance, products, and marketing &#8211; in other words, making money for the company or share holders. How about the CTO? Perhaps, but when you&#8217;re also responsible for maintaining the availability of your product delivery platform, the focus on confidentiality and integrity of the data maintained within the platform is often lost to availability of products and services to consumers. Furthermore, data does not typically sit stagnantly on systems, it gets consumed by both customer facing applications and internal application such as trend calculation and other business intelligence purposes that are likely not under the authority of the CTO.</p>
<p>By the position title alone, we can determine that the CI(S)O reports up to the CEO and is a peer to other &#8220;C&#8221; level executives such as the CFO (Chief Financial Officer), CP/DO (Chief Product/Development Officer), CTO (Chief Technology Officer), and COO (Chief Operating Officer). Generically, and as I&#8217;ve already stated, the CI(S)O is responsible for identifying, cataloging, and protecting ALL information assets, whether this data is externally or internally sourced. As such, the CI(S)O must interface with other executives in order to identify, document, and classify data assets.<span id="more-2104"></span></p>
<p>It feels like a good place for a quick tangent on data classification; each information asset within the company must be evaluated against a set of defined criteria to ensure that the level of protection applied to said assets is consistent with the risk associated with the loss or theft of the data. Incidentally, the responsibility for defining the classification levels and assigning appropriate properties to each level falls on the CI(S)O.</p>
<p>Once all information assets have been identified, solutions must be devised and implemented to ensure the data remains protected no matter where it travels or rests within the company&#8217;s (and partners) technical infrastructure. Partnerships with other executives are key to achieve this goal:</p>
<ul>
<li>The CI(S)O must interface with the CTO to ensure that solutions for network security/monitoring, host/server security, configuration/patch management, identity management, access controls, desktop security, and overall network and host health monitoring are in place. Please note that this is not an exhaustive list, just some key items to demonstrate the importance of the CI(S)O&#8217;s ability to interface with other executives and influence changes in other organizations within the same company.</li>
<li>The CI(S)O must interface with the CFO to ensure that appropriate data retention policies are in place, and that software, hardware, and communications paths used to transport or store sensitive employee data have appropriate levels of confidentiality, integrity, and non-repudiation.</li>
<li>The CI(S)O must interface with the COO to ensure that appropriate physical security controls, security awareness and security policy training programs, and employee accountability are in place.</li>
<li>The CI(S)O must interface with the CP/DO on implementing a robust software security lifecycle for applications and products that collect or display sensitive information.</li>
</ul>
<p>By no means is this meant to be an exhaustive list of CI(S)O responsibilities, but rather a select few to demonstrate that information security cannot be shared across multiple executive owners. With something as critical as securing consumer and corporate data against an ever growing number and diverse set of threats, accountability at the highest levels of the company is key to creating and enforcing good security policies, procedures, and solutions.</p>
<p>*For the purposes of this article, I&#8217;ve assumed that the titles Chief Information Officer and Chief Information Security Officer are one and the same. The CI(S)O&#8217;s roles is to ensure the security of information assets.</p>
<p><em><strong>Wade&#8217;s Bio</strong>: An IT Security professional in the Washington DC area, Wade works for a large Web Application Service Provider as a Senior Engineer on the IT Security Assurance Team. You can find Wade on Twitter <a href="http://twitter.com/wadew">@wadew</a> (you can also see him on our <a href="http://www.novainfosecportal.com/resources/nova-email-lists-networking/novainfosec-twits/">NovaInfosec Twits list</a>), and can read more of what he has to say on his blog at <a href="http://www.wadewoolwine.com/">WadeWoolwine.com</a>.</em></p>
<p style="text-align: center;">o o o o o</p>
<p style="text-align: center;">Many thanks to Wade for this excellent post. We hope that you&#8217;ll follow Wade&#8217;s lead and <a href="http://www.novainfosecportal.com/contact-us/">contact us</a> about becoming a guest poster for NovaInfosecPortal.com.</p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=What%21+No+CI%28S%29O%2A%3F+http%3A%2F%2Fj.mp%2FnJJgDf" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2009/09/09/what-no-ciso/&amp;t=What%21+No+CI%28S%29O%2A%3F" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/09/09/what-no-ciso/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

