Three ways to align security programs to enterprise strategy

omidomi

Level 71
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Forum Veteran
Apr 5, 2014
6,017
43,487
6,988
32
Fallout New Vegas :D
Among challenges faced by information security teams, one of the most common is how best to align the security program with the larger business. While everyone comes together around the idea that security breaches are bad, balancing the costs of preventing them against other enterprise priorities is a trickier proposition. Unified stakeholders often diverge when forced to choose between security and other values like profitability or ease of use. It gets even harder when organizations struggle simply to agree on how risk should be defined or what acceptable security risk really means.

Since all security programs depend upon business owners for resources, cooperation, and support, it's in every CISO and security manager's best interests to be able to translate the benefits of security into the language of enterprise strategy. That means outreach messaging designed to do more than just scare the pants off everyone. FUD tends to be a self-defeating tactic over time. The audience either grows numb to it, or begins to actively resent the security team as a "party of no!" that only exists to make life harder for everyone. When security is seen as an adversary and not a business partner, half the battle is lost.
 
  • Like
Reactions: kev216 and Alkajak
IT professionals get fired because they tell higher-ups things that the higher-ups don't want to hear - or - the higher-ups will adopt a risky security strategy and when the organization gets compromised they throw an IT professional, or two, or three under the bus as a scapegoat...

It's sickening, but the way of the world.