« Preserving our Information Security Heritage | Main | Security myths exposed »

Let's get real about information security

Wherever you go, or whatever you read, these days, it;s hard to escape security professionals and pundits that preach that information security and risk management are business enablers. Now that's certainly true. But we have to put this in perspective.

Such benefits help support the business case for security. And it's always helpful to communicate the nature of the subject in business terms. But let's get real. No business in their right mind would invest in security purely for the business benefits. There are many other, much more powerful enablers for business (like more advertising, a bigger sales force, or better customer relationship management) than security. And risk management is primarily used to provide credibility to decisions, rather than lead them.

Security and risk management are driven exclusively by incidents, and, as a consequence, by compliance and citizen concern. And addressing the latter two drivers requires a focus on the perception of your security capability, rather than the actual state of security. Because when you're truly secure, nobody will ever notice. That's the reality of information security.

Bookmark and Share


TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/40125

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on November 9, 2008 6:49 AM.

The previous post in this blog was Preserving our Information Security Heritage.

The next post in this blog is Security myths exposed.

Many more can be found on the main index page or by looking through the archives.