Here is a dangerous question to start the new year: Does your company actually need a security department? If you are doing CYA instead of CIA, the answer is probably no. Dark Reading
« The Road to the Security Cliff is Paved with Optionality | Main | Incentives and Decision Making »
The comments to this entry are closed.
I've been arguing for nearly 4 years that a security department is unnecessary these days. I disagree with you on the "CYA instead of CIA" quip, though. I think it comes down to organization and optimization. The business should be managing operational risk, and operations should own those remediation and management duties. A separate security department tends to decrease an organization's effectiveness.
One of my first posts on the topic was here in July 2009:
http://www.secureconsulting.net/2009/07/do-you-need-a-security-departm.html
More recently:
http://www.secureconsulting.net/2012/06/its-time-to-retire-security-fr.html
fwiw
-ben
Posted by: Ben Tomhave | January 09, 2013 at 01:01 PM
@Ben - Agree and I would go one step further: do you need IT at all? You could say this is what the Cloud is about. But really, we had IT back when few knew how to operate a computer. Not the case today. In my view you are either
a) developing a product
b) operating a product
c) working in customer service
There's no reason to separate "business" from "IT" its just business.
http://1raindrop.typepad.com/1_raindrop/2011/01/the-business-of-it.html
Posted by: gunnar | January 09, 2013 at 01:12 PM