
Calls grow for chief security officers...
Published: 10 April 2003 14:03 GMT
The creation of positions such as chief security officer (CSO), and a growing focus on security in enterprises more generally, has started to create interest in whether CIOs and IT managers should be involved in decisions relating to physical security.
Greg Ryan - from the network and integration services division of IBM Global Services in Australia - believes that greater communication between the IT department and the business about physical security is important.
Ryan said that some organisations in the past had not had the CIO involved in the company's physical security, because there was a separate security department which handled this area. However, he believed, the increasing need to link physical security systems into IT infrastructure meant a growing involvement by the IT department.
Increased return-on-investment of business infrastructure was another reason IT departments were becoming more involved in an enterprise's physical security, Ryan believed. If the security department and IT department are seen as working together, IT was seen as adding value, rather than just being a cost, Ryan said.
People should move away from the mindset of separating IT security and physical security, argues information security consultant Daniel Lewkovitz. Yet he also cautions that the actual implementation of IT and physical security systems shouldn't consequently be seen as requiring similar technical skills. "Someone who knows how to install a firewall may not know how to assess camera technology," he said.
But Lewkovitz said that over-riding concepts such as risk assessment, risk treatment and overall approaches were similar for physical and IT security. "The risk of anonymous hackers may be as great as someone coming and setting fire to your building," he said. "So the concepts are very similar - if you're protecting a computer, a person, or a building".
Lewkovitz also warned about taking a reactive approach to security, or using fear tactics. Instead, he suggested identifying the genuine risks to a particular organisation and treating those effectively.
Analysts are also finding increasing connection between physical and IT security in organisations. In a research note, industry analyst Gartner also commented that some enterprises were looking at combining information security and physical security departments under one roof. It credited this to an overlapping of responsibilities, such as investigations and user provisioning, as well as protecting organisational assets.
"This arrangement takes a strong management team and a lot of communication because the skillsets of each group are very different," it said.
Vivienne Fisher writes for ZDNet Australia
Drug Safety Officer (Pharmacovigilance) Thames Valley The new Drug Safety Officer will gain superb experience in drug safety working very closely ...
Market leading energy supplier currently seeks a market risk analyst, with physical energy asset exposure, to join their successful central London ...
Be prepared to have knowledge of job within three monthsIf courses are available may be held off site SC to determine relevance.To attend NEL Flow ...
Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Steve Ranger Editor's Blog: Is software's future now behind it? The industry is short on big ideas - at least for now
Tim Ferguson Is Salesforce.com sitting pretty for cloud wars? Comment: Software giants face a well prepared foe