Case Study
A CSO's First 100 Days On the Job
The CSO of IndyMac Bank shares his aggressive to-do list for his first 100 days on the job
By Scott Berinato
we have way too many security policies. That happens when you work tactically, ad hoc. Something
comes up and someone develops a policy regarding that specific incident. Soon enough, you have all
these policies and the only people reading all of them are internal audit. I want to develop a simple,
flexible security policy that follows the ISO framework.
tactical. I want to bring that down to about 40 percent. I'll do it by creating a strategy/architecture
group.
of our facilities. The next step will be to determine which facilities need to upgrade controls like
mantraps, surveillance and so forth.
need to think of security as an enabler of future business and a market differentiator. To do this my
team should work on projects that are forward-thinking while addressing present control concerns.
li>
Other stories by Scott Berinato
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



