CSO's desk Articles

Security pros must speak in one voice

Jennifer Bayuk, principal, Jennifer L. Bayuk LLC June 04, 2009

The role of a security professional in the vendor review process is to help identify which vendors are "critical" to the security of information assets.
 

Goodbye to security by obscurity

Willie Rushton owner and principle consultant, WLR & Associates May 01, 2009

The harsh reality is that many companies are unaware of the nature and extent of unauthorized information that is leaving their environment both electronically and physically. However, there are fundamental steps you can take to understand and prevent any potential exposure and risk of leakage of sensitive data.
 

The privacy & security advantage

Al Raymond, chief privacy officer, PHH Mortgage April 10, 2009

In this precarious financial environment, the focus for many companies is now on keeping the existing customers satisfied, rather than worrying only about adding new ones to the fold
 

Leading through the good and bad

Jaime Chanaga, CEO, The CSO Board March 05, 2009

As the drumbeat of negative economic updates seems to overwhelm our daily news cycles, we tend to forget that at the heart of any business engine is people.
 

Security needs a governing body

Richard Starnes, president, ISSA Bluegrass Chapter February 05, 2009

Given the issues that we face daily, given our liability, legal and regulatory environments, the seriousness of what we do, and the effect it has on our society, it is time for us, our industry associations and certification entities, to begin the dialogue surrounding the formation of a governing body with the force of law
 

Risk management: Common assessments criteria

Stephen Scharf, SVP & global CISO, Experian January 01, 2009

Conducting security assessments of critical service providers is an essential part of an enterprise risk management program.
 

Security pro versus organization

Shannon Culp, CSO for a Midwest health care organization December 04, 2008

It's refreshing to me that more and more organizations are starting to realize the value of having a CISO that is experienced and accountable for information security.
 

A standard for payment security

Rob Tourt, chair, PCI Security Standards Council November 04, 2008

Rob Tourt, chair of the PCI Security Standards Council, outlines developments on PCI DSS requirements.
 

Managing risk in hard times

Dave Cullinane, CISO, eBay October 06, 2008

Dealing with a security issue itself is clearly the priority - stopping the damage and doing triage. Once things are under control, a more detailed analysis should take place.
 

Collaborating against e-crime

Michael Barrett, CISO, PayPal September 01, 2008

E-commerce is not only attracting online consumers, it's increasingly attracting cybercriminals.