Home > CIO News > IT security trends move toward information risk management
CIO News:
EMAIL THIS

IT security trends move toward information risk management

By Linda Tucci, Senior News Writer
17 Jan 2008 | SearchCIO.com

IT news and analysis for CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

IT security trends are moving away from a tactical, technical focus on IT operations to "information risk management." Bring in the consultants! The evolution toward information risk management is shaking up the way IT security works at many large organizations.

More on information security
Web services transform security mind-set 

E-discovery and litigation for CIOs 

Jonathan Penn, a security analyst at Forrester Research Inc. in Cambridge, Mass., has singled out five trends in IT security that are on your chief information security officer's agenda in 2008:

  1. GRC: IT governance, IT risk management and IT compliance (GRC) will converge into one discipline, with greater attention paid to metrics, staffing and optimal organizational structure.
  2. IT security operations: As IT security technology becomes commoditized and embedded in IT infrastructure, security organizations will split into two groups: strategy teams focusing on business issues of risk management, and operational teams overseeing the technical aspects.
  3. Application security: Applications are a prime target for attackers because they deal with sensitive data. A "fix it when danger strikes" approach is giving way to proactive security programs that span the application lifecycle, from bright idea to operation.
  4. Datacentric security: In an age of many business partners, this is the mammoth effort to classify data in order to determine who gets to see it and how to protect it. This cannot be done in a vacuum and requires close communication with business leaders.
  5. Digital investigations, forensics and e-discovery: This can be a scary and daunting area -- especially e-discovery, in which organizations are still struggling to figure out what constitutes best practices.

Source: Forrester Research Inc. "Five Trends That Will Shape The IT Security Profession in 2008," Jonathan Penn.



Tags: Enterprise risk managementEnterprise information security managementStrategy: Take stock of your risksVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Enterprise risk management
Email archiving solutions and strategies for enterprise CIOs
For CIOs, email deletion scandal shows need for email retention policy
Swine flu preparedness: Business continuity during an H1N1 outbreak
Talking swine flu and Conficker with the CIO of the CDC
Tips from the CDC's CIO on H1N1 flu preparedness
Tips for business continuity and contingency planning for swine flu
Enterprise risk management quiz for CIOs
Enterprise risk management solutions for CIOs
Gartner: Future IT security jobs to focus on risk management strategy
Business continuity plan needs the right leader, metrics to succeed

Enterprise information security management
Talking swine flu and Conficker with the CIO of the CDC
Network access control: Security advice for enterprise CIOs
Evaluating network access control: NAC policy enforcement matters
Enterprise risk management quiz for CIOs
Network access control now addresses multiple needs
Enterprise risk management solutions for CIOs
Gartner: Future IT security jobs to focus on risk management strategy
Avoiding gotchas of security tools and global data privacy laws
Security standards to help manage compliance for those federal funds
Information security and IT governance guides for CIOs

Strategy: Take stock of your risks
Enterprise risk management solutions for CIOs
Gartner: Future IT security jobs to focus on risk management strategy
Sustainability risk management: Beyond green IT
Outsourcing deals no good if contract is weak
Career advice for CIOs: Four qualities of a leader and more
'Millennials' buck IT security policies
Vetted IT negotiations reduce risk of project failure
Business process management: Avoiding the pitfalls
IT risk moves higher on security radar, report finds
IT security management policies good for the business

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
GRC (governance, risk management and compliance) software  (SearchCIO.com)
sustainability risk management (SRM)  (SearchCIO.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



CIO solution center has news, research, and guides to assist the unique challenges of the CIO
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts