Q&A
Cyber Security Versus Physical Security: Smackdown!
Two former colleagues square off to debate the division of roles and responsibilities of security leaders.
By Scott Berinato
Campbell: I'd underscore that. My complaint with having the CISO as part of the IT department is you get the fox in the henhouse. Where do you have an honest set of controls that can make it before the audit committee in its own right?
Spernow: I've actually fought that battle [at the Georgia Student Finance Commission] and won. The CIO should be concerned with how to maintain the infrastructure today and how to plan for its future. The CISO should be looking at the ramifications of new technologies the CIO wants to adopt. [For more on this, see "How to Rope in Rowdy Technologies" at www.csoonline .com/printlinks.]
Campbell: Let me ask you this, then. To what extent does a CISO's background and experience as an information security professional detract from his ability to effectively lead and strategize for the other aspects of security that a CSO controls?
Spernow: They become technocentric. I've seen CISOs try to integrate authentication log-ins with physical security controls like access cards. That's usually where they stop because it ends up not working. At first, the locked door and exposed trash bins and all the other physical security issues associated with controlling building entry and exit...
Campbell: I'm reminded of a conversation I had with a CISO. I basically challenged him to tell me how the greater security organization could be engaged in the information security program. After a couple of minutes of pondering, he said, "Well, I suppose they could collect the trash."
george campbell
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



