How To

How to Manage Security Halfway Around the World

Tips for managing security in a global company

By Todd Datz

December 01, 2005CSO

Different cultures. Unstable political environments. Language barriers. CSOs in global companies face many a challenge as they try to manage security worldwide. One of the biggest challenges? A good number of your security managers reside in functions other than corporate security, so security is often a part-time gig managed by people with part-time security training. There's no ironclad set of rules or policies that all those employees can follow.

"The key I keep in mind when developing our security standards is don't try to pound a square peg into a round hole," says Anton Bommersbach, head of global security at gum maker Wm. Wrigley Jr. Co. This story outlines best practices and useful tips on how to maintain effective security around the world, particularly in making the most of those folks from other departments who serve as your feet on the street in distant locales.

Determine What Kind of Security Department You Are

The first step to take when thinking about global security strategy is to ask the question, What kind of security department do I have? Jim Brooks, senior VP of crisis and security management at Control Risks Group, says a traditional department tends to have a larger staff, a facilities-oriented approach and a predilection to do things in-house. The current trend, he says, is toward an advisory-oriented department that is smaller in staff and strategic in its thinking, and acts as a risk management function; for example, the security head would likely be involved in business continuity and disaster recovery.

Brooks believes the latter type of security department is better suited to a global environment. "I think the most efficient department from a pure business sense is scalable without permanent mass," says Brooks. "It's inefficient for multinationals to think they can cost-efficiently house all the experts in-house to treat all global exposures. It doesn't make sense to employ all that staff." However, he adds, if transforming your security department from old guard to new guard is culturally unpalatable, don't force the issue.

Form Security Partnerships with Business Units and Even Other Companies

If Brooks is right, and large companies with lots of global operations typically don't have enough security personnel to parcel out to every factory, office or site, that means that managers or directors from other functions also man the security post in addition to their other duties. And that's all the more reason for CSOs to keep in close contact with those employees to understand the unique conditions of that location.

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

IS/IT Project Mgt. Credentials From Villanova - 100% Online

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Data Protection: Challenges for the Traveling User

Key strategies for C-level executives and security staff

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage

Configuration Assessment: Choosing the Right Solution

Revolutionizing Endpoint Security with a Single Agent

Envision Identity-Based Access Control for the Datacenter

Rolling the dice with your security? Take the Self-Assessment Test now

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

Digital Identity Protection and Data Security Get Personal

The Case for Business Software Assurance ~ Securing Your Applications

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era