Case Study

A CSO's First 100 Days On the Job

The CSO of IndyMac Bank shares his aggressive to-do list for his first 100 days on the job

By Scott Berinato

Page 2


  • Streamline policies. Despite the fact that we revamped that one policy, overall

    we have way too many security policies. That happens when you work tactically, ad hoc. Something

    comes up and someone develops a policy regarding that specific incident. Soon enough, you have all

    these policies and the only people reading all of them are internal audit. I want to develop a simple,

    flexible security policy that follows the ISO framework.


  • Balance tactical and strategic. When I got here, security was 100 percent

    tactical. I want to bring that down to about 40 percent. I'll do it by creating a strategy/architecture

    group.


  • Rate all facilities' security controls. We've created gold and silver ratings for all

    of our facilities. The next step will be to determine which facilities need to upgrade controls like

    mantraps, surveillance and so forth.


  • Rehabilitate the reputation of the security group. The main issue is people

    need to think of security as an enabler of future business and a market differentiator. To do this my

    team should work on projects that are forward-thinking while addressing present control concerns.

    li>


    Other stories by Scott Berinato

  • $firstKeyword

    RESOURCE CENTER
    Loading...
    VIRTUAL CONFERENCE
    Security Directions: A Virtual Conference

    Security Directions Available On Demand Sept. 30 - Dec. 30

    Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

    » Register Now

    WEBCAST
    Protecting PII: How to Work with IT to Manage Risk

    Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

    » View this Webcast

    Featured Sponsors