Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Four good reasons for Security to talk to HR

Dogs and cats living together? Yes, but necessarily so

Neither information technology nor security managers fire people in most organizations. That plain reality seems to escape some in the industry, where offended security administrators declare that disabling the anti-virus program is grounds for demotion or an IT manager finding unlicensed media makes arrangements for someone to make the cardboard box commute.

Too often, security folk are surprised and disappointed when the perpetrator is slapped on the wrist, or the incident quietly tabled without reprimand. Why the disjoint? Because they didn't coordinate with human resources, and because there's no clarity about the severity or risk from the behavior, even incidents that ought to garner serious attention don't.

The solution is to get right with Human Resources long before the incident. I know -- like dogs and cats living together, the notion of touchy-feely human resources personnel working together with hard and graceless IT security geeks may portend the coming of the End Times. But there are a handful of topics that require collaboration. By addressing them before there's an incident, a lot of pain and frustration can be avoided.

Identity and authentication

The initial establishment of identity for a new hire -- acquiring driver's licenses and associated documents -- is a management task specific to HR. When identity is established, and the person who showed up is sufficiently authenticated as that person, we say that initial identification and authentication or "initial I&A" is complete.

This is never an automated task. This is also never an IT task. If someone shows up at the IT helpdesk asking for an account, and there's no HR record of initial I&A, all sorts of alarm bells ought to go off. Unless there's a specific exception -- perhaps the granting of temporary IDs to vendors when a business unit's contract serves as initial I&A -- IT should never, ever be in the business of determining if a person exists or not.

It's one of the most common errors I see, but initial I&A ought not be confused with the implementation of roles and rights. Only after the management decision to hire someone is processed by HR, can a person's online persona be connected to a set of tasks, specific role, salary, and the other trappings of a job. Confusing these different steps means stepping on HR's toes, after which conflict, confusion and weakened security are inevitable.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: eBay, Educause, ISO, Microsoft, Minotaur, Persona, VIA
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • Enabling Agile and Intelligent Businesses
    In the last 3 to 5 years there has been widespread adoption of SOA with businesses making significant economic investments in service-enabling their IT systems. Looking to enable your business for efficient IT execution? Read this white paper now.
    Learn more »
  • SOA Adoption for Dummies
    This book describes our approach to SOA adoption, which we call SOA rocket science. SOA adoption, like a real-world rocket, experiences a danger zone between blast-off and the weightlessness of orbit. When fully realized, SOA can transform your business. But until firmly established, your SOA dreams can plummet back to earth.
    Learn more »
  • IDC Forecast: Worldwide Purpose - Built Backup Appliance 2011 – 2015, Forecast Update: Explosive Growth in 2011
    This IDC Forecast Update provides share positions for revenue and raw capacity for nine named PBBA vendors for the first half of 2011. In addition, this study provides the market size and a five-year forecast for the worldwide PBBA market as part of IDC's Storage Solutions coverage. The five-year forecast includes total factory revenue and raw capacity in terabytes through 2012. The worldwide PBBA market covers both open system-and mainframe-attached products.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.