Positive Security, Risk Management, and Compliance
Charles H. Le Grand · EDPACS · 2013
IT security and risk management professionals have traditionally focused on what can go wrong and the tools to protect and secure information and systems. That focus leads to identifying the costs of security and controls more so than their benefits. The benefits have typically been seen as protecting against negative effects of security incidents. But this article shifts the focus to the benefits of effective security and control practices in enabling the new technologies that will keep an organization innovative and competitive. It is not a treatise on specific security controls or metrics, the incidence and costs of security incidents, or the elements of risk analysis. Those are important topics, and are well covered in security and risk management literature. 1 1. See, for example: • The Institute of Internal Auditors: http://www.theiia.org • ISACA: http:// http://www.isaca.org • The IT Process Institute: http://www.itpi.org • National Institute of Standards and Technology (NIST), Federal Information Processing Standards Special Publications (FIPS Special Pubs) including established as well as draft publications open for public review and to offer comments: http://csrc.nist.gov/publications/PubsDrafts.html#SP-800-53-Rev.% 204 • The Phoenix Project: http://itrevolution.com/books/phoenix-project-devops-novel/ • PRAGMATIC Security Metrics (a new book): http://www.securitymetametrics.com/ • The SANS Institute—Security Resources: http://www.sans. org/security-resources/ • SANS Survey on Application Security Programs and Practices December 2012: http://www.sans.org/reading_room/analysts_ program/sans_survey_appsec.pdf • Securosis is an information security research and advisory firm dedicated to transparency, objectivity, and quality, and totally obsessed with improving the practice of information security: https://securosis.com/ An apology to all the other great sources and resources, as this publication is not big enough to cover them all. Rather, this article addresses the importance of an enterprise view of the value of integrating effective controls into technology planning, justification, budgeting, scheduling, and all the other steps involved in implementing new and emerging technologies. Effective security is clearly integral to managing the burgeoning risks associated with new technologies, so it is time for security and risk professionals make sure security is factored into return on investment calculations with the benefits including staying in business and remaining competitive.