Q&A

Cyber Security Versus Physical Security: Smackdown!

Two former colleagues square off to debate the division of roles and responsibilities of security leaders.

By Scott Berinato

Page 7

Spernow: But how do you get around that? It's tough, because you've got to essentially convert people to your way of thinking without offending them, and make them understand what you're trying to do and why you're doing it. I mean, that's probably the toughest job that I have on a daily basis.

Campbell: But what happens when it hits the fan? We need a set of protocols between the two organizations so that, when there's an intrusion, someone separate from the IT side is making sure that evidence is preserved, that logs are preserved. It's like arson: IT wants to put the fire out. I'm looking for evidence after the fire is out.

Spernow: But if you try to do it during the incident, you're shooting yourself in the footbenefitting the bad guys more than the good guys. My point is the opposite of George's. The CISO needs to be put in place to be entirely in charge of an incident. I don't suggest to the people I talk to that the CSO be part of an investigation. [At least not] until it gets to the point where we're talking to employees or to people outside the company, where CSOs normally have the contacts to make it happen. When it's internal to the network, then the CISO should be in charge.

Campbell: Getting back to the model Bill has adoptedan acknowledgement that the CISO function needs to be outside of IT department, correct Bill?

Spernow: Always, always. It's the biggest battle I've had here. If I see an organization where the CISO reports to some IT component, I see a position that's not working, guaranteed. The conflict of interest is just too much to overcome. Having the CISO report to IT, it's a death blow.

Other stories by Scott Berinato

george campbell

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors