Follow Us

Security disables business, says CERT boffin

Death to the technologists.

Security has to evolve into something that supports business, rather than the other way around, according to a senior member of the technical staff at Carnegie Mellon University's Computer Emergency Response Team (CERT).

Security has got a bad rap in today's enterprises, said Lisa Young. The tendency is to want to start locking things down. This way security has become something that disables, not enables, business, she added.

Young said this was still an area where boxes and technology ruled. "Solving your security problems by buying another box is just wishful thinking. But security is bigger than that," Young said. "As security managers it's up to us to elevate the profession, and include both people, processes, not just technology.

She added that IT managers hadn't thought of a way of incorporating security as part of the business process. "People just haven't thought of security as a discipline that can be measured, managed and mapped. It's a new way of looking at it," Young said.

To simplify efforts to make changes to security strategy, Young's development team at CERT has developed the Resiliency Engineering Framework (REF), which was launched last year.

It doesn't compete with other frameworks, such as ITIL. REF identifies enterprise-wide processes for managing operational resiliency – including everything from training to compliance management – and provides a structure from which an organisation can start to improve.

"You can reduce cost, eliminate duplicate efforts and improve compliance efforts, for example," Young said.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *