Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Security lessons from the top

IT vendors have had to learn data protection best practices early


At IBM, CIO Mark Hennessy also stressed the importance of delegating to his team of security experts and of conducting near-constant risk assessment. But even with that delegation, security remains a top focus for him, he said. "The world is changing, and there are a lot of new realities around security to address. Fostering stronger security across the board is a core tenet, as it helps to bring more value to everything we do," he said. "We want to make our employees more comfortable and more productive, and drive greater success for the clients we serve, so it's something we constantly need to remain focused on," he added.

The security-vs.-complexity challenge
Malcolm Harkins, general manager of Intel's Information Risk and Security unit, works directly with the chip giant's CIO John Johnson on issues of internal operational security and compliance. Harkins said that one of the biggest challenges that organizations such as Intel face is the process of improving security in the face of rapidly advancing IT complexity.

On top of that, ongoing efforts to lower the total cost of securing a company the size of Intel -- while keeping up with emerging threats and regulations -- is driving the firm to seek greater standardization in some areas, and to integrate larger groups of technologies in others. "We currently have over 40 individual security software and hardware providers that we are doing business with, and that's a lot of different pieces to have to integrate," Harkins said. "It's almost crazy from an IT standpoint, so we want to employ greater levels of standardization to help us with issues of consistency; we'll always have a very heterogeneous environment, but we really need a more consistent set of tools. The more standardization you have, the easier it is to make things more secure."

One of the most crucial steps any company can take in terms of improving its security is driving understanding of the attacks and laws across their highest executive ranks and ensuring that leaders who become involved in matters of security maintain realistic goals and objectives, Harkins said.

But that does not mean being heavy-handed in terms of the security levels demand, he noted. C-level executives who take an extremely conservative approach and desire to aggressively lock down all their IT systems may in fact do more harm than good, he said. "Some companies believe that by severely limiting the use of technologies that pose risks, they are improving their defenses, but the truth is they may just be creating a false sense of security," Harkins said.

"In reality, they are limiting the ability of their business to operate effectively and are increasing risk by creating barriers and policies that can't be enforced practically," he said. In IT, "you have to work with [C-suite] to change their approach from one that is focused on responding to fears to one that is focused on key controls that solve real problems. You have to have executive buy-in, but by taking the wider approach of considering legal, compliance, and security issues together, you will end up with stronger protection, lower costs, and less complexity."

The original version of this story disclosed a different name as Intel's CIO but has now been corrected. InfoWorld regrets the error.

Matt Hines is a senior writer at InfoWorld.
« PREVIOUS PAGE | 1 | 2 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Virtualization: A Step by Step Approach to Success
Your virtual machines can be up and running in a matter of minutes. HP and Citrix have integrated XenServer with HP ProLiant servers and management tools, powered by hardware-assisted Intel Virtualization Technology to enable high- performance, cost-savings solutions for server consolidation and disaster recovery. Sponsor: HP

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 08/29/2008

Microsoft will focus on performance issues in Windows 7 and IE8, Qualcomm...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist