Who Will Prosper In The Changing World of Security?
Not all the news is bad. Many security managers are prospering. Three of the most effective approaches we have seen are: 1. Documenting risk reduction accomplishments. Security managers have learned that if they don’t prove the risk reduction they have accomplished – the potential problems that they have prevented – senior management will not understand or appreciate their contribution. Of course, the improvements must be auditable; they cannot be hollow claims. That’s one of the big reasons many security organizations have shifted from vulnerability testing, where the tools find theoretical holes, to penetration testing where the holes are proven. 2. Taking a leadership role in a merged security and operations group. A new, highly paid job is emerging inside large IT operations groups. Its holder has complete responsibility for ensuring that security is fully implemented in every system in the organization. By being inside IT operations and by proving he or she understands all the sys