Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

How great IT security leaders succeed

Forrester identifies some surprising attributes that make for the best-performing CISOs


As the threat of attack, both external and internal, continues to take root and as data-handling regulations continue to proliferate, the role of a chief information security officer appears to be growing more complex by the day. Many CISOs are doing an admirable job of stemming the tide of data loss and keeping their heads above water around compliance. But some IT security leaders are doing it better than the rest, according to a recent Forrester Research report, which has identified several characteristics that make these top CISOs more successful than their peers.

Beyond predictable recommendations such as having a close relationship with their employer's business leaders and making security a pervasive issue across their entire organizations, several unexpected practices arose during Forrester's discussions with users, vendors, and regulators.

A moral compass is the key to success
The top finding was that truly effective CISOs must have a strong moral compass that allows them to lead as much by example as they command respect via mandate. "CISOs are expected to have a certain level of technical skill, but the character of the person really drives a lot of the success that they might have in this position," said Khalid Kark, a Forrester analyst and the report's chief author.

"Having the integrity, the visibility, and letting people know that you as an individual will always do the right thing is of great importance when you are being trusted to protect a lot of sensitive information." Other C-level executives may be able to get away with taking sides in corporate standoffs or going behind people's backs to accomplish their goals, but CISOs who expect to garner the level of respect needed to carry out their jobs most effectively must emit a persona of undeniable trustworthiness.

"Before doing the research, I wouldn't have guessed how important this aspect might have been, even having managed security operations myself," said Kark. "But it became clear that this is a characteristic that many people really value in a CISO. One of the issues that these executives face is that it takes time to build trust, and if you have that [moral] compass where you instinctively know what [is right] to do, you can achieve that [trust] in a shorter timeframe."

Also important to gaining that trust and executive buy-in is an ability to work with "the corporate psyche," as well as balancing the CISO position's political and policing roles.

Flexibility, patience, business acumen, and mentoring are other keys
Other key attributes of the most successful CISOs include having the flexibility to look for creative solutions to problems and move quickly from one project to the next, remaining patient whenever possible, and running security as if it were a business unit. That latter talent requires the ability to gather important security and compliance data, plus knowing how to use it to defend related budget items and project work.

Matt Hines is a senior writer at InfoWorld.
Continued
1 | 2 | NEXT PAGE » 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





TAKE CONTROL OF YOUR CONTENT- LEVERAGE MICROSOFT SHAREPOINT
Microsoft Office SharePoint Server (MOSS) offers core content management designed for a broad user population. Attend this webcast to learn how to implement a strategy that allows for the coexistence of both MOSS and advanced ECM solution within the same IT environment. Sponsor: IBM

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist