In Brief
Three CSOs Offer Security Views from Around the World
CSOs at big companies overseas share a global approach
By Kathleen Carr
September 30, 2004
—
CSO
—
Whether the view is from Europe or Australia, CSOs look at their roles as part of a global effort to manage risks and protect assets. The three CSOs we consulted via e-mail
John Geurts
Executive General Manager for Group Security, Commonwealth Bank of Australia
At Sydney-based Commonwealth Bank, John Geurts, executive general manager for group security, says it's important for his bank
"We recently conducted a review of our practices against several leading financial services companies in the United States and the United Kingdom," Geurts writes. "It was pleasing to see that our structure and practice had much in common with leading thinking, and that security management is maturing in light of the threat and technological environment we are faced with."
Geurts says his role encompasses all aspects of security
And that relationship between infor-mation security and fraud
As for government regulation of security, Geurts advocates a hands-off, yet collaborative approach. He says government "should permit greater collaboration in sharing threat information with business. They should not seek to regulate on matters they do not fully understand in a free market."
Urho Ilmonen
CSO, Nokia, Finland
Urho Ilmonen, CSO of Nokia in Espoo, Finland, sounds like a spokesman for his industry colleagues when he says that information security is top-of-mind for high-tech companies worldwide.
"The current strained commercial situation and the rapid development of new competitors has fostered a market for technical and financial information, often sought after by investigation and information-gathering organizations of all shapes and kinds," he writes.
Information technology has another impact on Nokia, the $36.2 billion maker of mobile phones and other communications: It's made Ilmonen resigned to the idea that outsourcing is here to stay. This adds a challenge for CSOs, he says, because while the scope of activities has not grown, the volume has: "As we regard the outsourcing companies as members of the extended enterprise, we need to treat them securitywise in the same way [as our company], ensuring the same good level in security at their premises and operations that we provide in-house."
global security
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



