Skip to page content

The State of Security

News. Trends. Insights.
cameras

Ben Rothke on the Five Habits of Highly Secure Organizations

There are five habits of highly secure organizations, said Ben Rothke (@benrothke), Manager – Corporate Services Information Security at Wyndham Worldwide.

Rothke was about to give a presentation on this very subject at the 2013 RSA Conference in San Francisco, but he gave us a sneak preview on the show floor just beforehand.

They may seem simple to many of us, but ask yourself, are all five effectively being deployed in your organization? Take a look and ask yourself if they are.

  1. Have a CISO: Somebody needs to drive security. For example, a Chief Financial Officer is critical for driving finances. Similarly, a Chief Information Security Officer is critical for spearheading the company’s security practice.
  2. Risk Management: Risk drives everything. The CISO understands the risks and threats the organization faces and designs a security program around that. This must be customized and not a series of standard “best practices.”
  3. Invest in people not products: “The cost of hardware and software purchased has no corresponding effect to the level of security,” said Rothke. A company that has great talent using open source products will be more secure than a company that spends millions on proprietary tools but doesn’t intrinsically know how to use them.
  4. Policies and procedures: It’s very important to have standardization across all business units and processes. You want the firewall installed and managed in one location to be installed and managed the same way in another location. “If things aren’t done via standard processes you’ll have inconsistencies and that’s where security breaches and mistakes happen. When you don’t have common procedures and common practices things are done ad hoc, and ad hoc is the enemy of good security,” warned Rothke.
  5. Awareness – People have to have situational awareness of what they’re doing. For example, if you don’t have effective key management all the security you have will go up in smithereens, said Rothke.

 

Image of cameras courtesy of Shutterstock


Tags: , , , , , , , , , , ,

Categories: ,


This post was written by…

has contributed 142 posts to The State of Security.

Twitter @dspark

Google+ David Spark

David Spark is a veteran tech journalist and founder of Spark Media Solutions, a media consulting and production company. Acting as the "media" of "social media," Spark Media Solutions helps its clients be seen as leading voices in their field through brand-quality media production and distribution through top tier media channels.

Leave a Reply