Undercover
Why Security Convergence Is Elusive
Last month, CSO's editor asked why CSOs can't all just get along in a world of converged security management. The problem is that we've got to raise our profiles in the corporate world first.
By Anonymous
Where is security's importance recognized in the volumes of recent academic discovery on corporate integrity? Where is security's role acknowledged as part of the management lexicon on governance? Shouldn't we find evidence of shared ownership of security risk in newly energized governance models? Have we CSOs established a pattern of linked threats, vulnerabilities, risks and countermeasures to drive corporate risk management models?
Selectively, yes. But generally, no. We have a lot of work to do.In Search of ConvergenceThe editor's letter also asserts that there's an "evolutionary path toward a converged model of governance." What is this nirvana, this "blissful state of unification"?
Just for the record, I have served in both types of models: unification and grieving separation. The first was a converged, wholly integrated security program; the second was a more balkanized place, where information security was initially split between risk and CIO
So what are we converging here? Remember, there's a bigger picture involved than the security function. I'm still hung up on the lack of progress in converging security into the larger corporate governance scheme, not merely a converged assemblage of security parts. What is the embarkation point for this evolutionary path? Should the incremental steps begin at the bottom, with security pushing its way in? Or from the top, launched as an epiphany from the CEO?
There are signs of life. I'm encouraged that a number of my CSO colleagues are taking on new duties associated with a redefined notion of corporate governance (often not including infosec), but I worry about the shelf life of these limited steps. We really need to penetrate MBA programs, question the limited scope of established risk-management concepts and better advertise what we bring to the governance table. We are making selective inroads with our security colleagues, but not with our senior management clientele.
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



