ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    IT told to fix security without 'bothering' business

Security teams shouldn’t let the safety of systems fall on employees following policy, but instead should take ownership of their roles, one expert has said.

By Jennifer Scott, 11 Mar 2010 at 14:50

Security team

Employee awareness of security issues may be important, but it is down to the security team to take ownership of the systems and their jobs to keep the company safe.

This was the view of Kim Aarenstrup, chief information and security officer (CISO) for Maersk, in a keynote speech at the Forrester Security Forum in London today.

Although he claimed security issues were now a “business concern with a tech component,” he said it was up to the technical security team to deal with it, not the rest of the business.

“What we want to do is take care of a lot of the security challenges… without really bothering the business side. They have their own challenges [and] the CEO expects the CISO, who he is paying a salary, to take care of these things,” said Aarenstrup.

Although this may sound like an obvious way security teams should be operating, Aarenstrup pointed out that a lot of security had been done previously via saying no and issuing policies, leaving the safety of systems in the trust of the employees using them.

He said: “There is no doubt that [employee] awareness is important on certain aspects, very important, but asking employees to try to take care of everything? Really we are not going to leave the capability of security, which is very complex, in the protection of our employees.”

“They should look after those areas where they are at their best and we should look after this one.”

With new technologies such as cloud computing and virtualisation, Aarenstrup concluded that security teams needed to “get rid of the old dogmatic thinking” and “conservatism” that previously dominated the industry.

He claimed that rather than saying "no" to something that business users request because it may seem risky, security teams should find a way to make it safe.

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

 Sponsored Links

advertisement
advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement