Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.

Category Archives: CSO/CISO Perspectives

Security in Times of Crisis

– Who would have thought, when I wrote my three-part column on “Security and Change” (here, here and here) that all three aspects would hit us at the same time. There was Hurricane Ike, the disappearance and takeovers of major financial institutions, and the massive credit freeze…

Corporate Governance: A Dirty Word or a Dirty Job?

– Corporate governance is in the limelight. No one wanted it, not many embrace it. But it’s here and here to stay, thanks to the horrifying outcomes vis-a-vis criminal activity leading to the failures of Enron, Worldcomm and the likes. In the newly published anthology, CISO Leadership:…

Governance, Risk Management, Compliance (pt. 1): Form over Content?

– Just a couple of months ago I had a discussion with a colleague, Jim Reavis, on the validity of the recent interest in GRC (Governance, Risk management, Compliance), whereby vendors are peddling systems and services to integrate all three areas. I had said to Jim that I thought GRC was the…

Business Drivers For Information Security: Who Needs Them Anyway?

– Security needs to be done to protect the information assets from all the hackers, thieves, criminals and people waiting to steal laptops and data as well as those disgruntled employees that are trying to sabotage the networks, right? Everyone knows that, we need to invest much more money to solve…

IT and Infosec Insourcing: Could You Do It If You Wanted To?

– There was an article by Timothy Aeppel on the front page of the June 13, 2008 issue of The Wall Street Journal with the title “Stung by Soaring Transport Cost, Factories Bring Jobs Home Again” (subscription required). The article is about manufacturers bringing back some of their…