CIO

Stories by: J.F. Rice

  • +

    Security Manager's Journal: SOX is out of control 10 May, 2012 02:48:23

    In my last column, I talked about how time-consuming SOX compliance is for companies like mine. Unfortunately, it's about to get worse.
  • +

    Security Manager's Journal: Shrinking staff, and a time crunch 03 April, 2012 03:35:11

    Today is the last day of the quarter in my company's financial calendar, and that means it's SOX time. I'm wrapping up four quarterly Sarbanes-Oxley Act controls that have to be completed by the end of the day -- reviewing security settings on our financial servers, reviewing the activities of system administrators on those servers, checking for inactive accounts that haven't been logged into in over 90 days, and checking the vulnerability report. SOX activities are remarkably time-consuming.
  • +

    Security Manager's Journal: When executives want to be above the law 06 March, 2012 00:29:30

    What do you do when your company's executives insist on special treatment that violates your security policy? This week, I ran into this problem.
  • +

    Security Manager's Journal: Should physical security belong to us? 03 February, 2012 08:22:00

    I've always wanted to be responsible for physical security. I never understood why the security of computers, networks and data is managed by a different department than the security of doors, windows and cameras. The same principles apply in both worlds. And let's face it: Physical security is actually run on computers. So I think it's perfectly natural for information security to own it.
  • +

    Security Manager's Journal: End of year brings SOX, deadlines and layoffs 11 January, 2012 04:58:15

    The end of the year was busy for me and my team. Already swamped with Sarbanes-Oxley audit activities and end-of-year project deadlines, even more security work came our way after a new round of layoffs.
  • +

    Security Manager's Journal: Why not spring for Cadillac security? 17 November, 2011 05:36:17

    Cadillac or Kia? How much security is enough, and how much is too much? Can you even have too much security?
  • +

    Security Manager's Journal: Sometimes even managers get their hands dirty 29 October, 2011 04:45:54

    With only a skeleton crew, and no budget for consultants, I've been borrowing IT staff from other departments to get things done. That's been helpful, but none of them has the specific skills to analyze complex firewall and NAT rules.
  • +

    New economic woes lead to deep cuts 20 August, 2011 05:03:00

    If you've been watching the stock market this month, you know that, economically speaking, things are going the wrong way. We seemed to be in a period of economic recovery, but now, whatever recovery we might have been having seems to have fallen right through, like piping-hot coffee melting the bottom of a cheap cup. Whether or not you consider stock market activity as a representation of the overall economy, I can tell you that my company seems to be falling on hard times as well.
  • +

    Security manager's journal: Helping in-house developers 29 March, 2011 05:53:00

    This week I found out that my company is developing software in-house. Until now I hadn't known that we were a software development shop, but I guess I shouldn't be surprised. Most companies that I've been with have developed their own software for one purpose or another. I only learned about this software development project when one of the programmers approached me to ask about the best way to store usernames and passwords in the application's database. Yes, that's right -- they built the authentication right inside the application, instead of calling out to an external authentication source.
  • +

    Security that doesn't get in the way 26 February, 2011 07:26:00

    I was on the road last week, attending the RSA security conference in San Francisco, which is a great place to run into colleagues. Afterwards, I visited Disneyland, which, despite being in the same state, is surprisingly far away. What do these places have in common? Security.
  • +

    The need for real security in a virtual world 25 June, 2010 08:45:00

    In a recent column, my Security Manager's Journal counterpart, Mathias Thurman, wrote about securing virtual desktop environments. My company is going through the same exercise of evaluating VDI as a replacement for traditional desktops. As Mathias pointed out, the concept of virtualizing the applications that run on the system does not substantially change the threat landscape, nor does it modify the countermeasures we put in place to protect against those threats.
Additional Resources
Zones
Zone logoZones provide focussed content from CIO and leading technology partners.
RSS Feeds
Polls

Does a successful CIO need to master the art of confrontation?

Yes, learning to negotiate through confrontation is a key skill
No, confrontation is the last resort of any kind of communication
View Results
 

Wondering how to improve your business with UC on an IP Network?

Join Computerworld's Live Webinar where we will address the move many companies are making towards IP based voice services (SIP trunking, VoIP) and look at how they are using a single connection for data and voice rather than separate lines. Learn about the latest in IP networks and how it can help your organisation.

Wednesday 25th November 2009, Time 10.30 am EST (Sydney, Australia) Screening at your desk

Register now

Most Popular Whitepapers

Recent comments
Zones
SAS Resource Centre

This Resource Centre hosts a wealth of thought leadership articles, whitepapers, and success videos, to help you make the most out of your corporate information in order to swiftly make sound business decisions to survive and thrive in the current economic climate.

Oracle Resource Centre

News, Features and the latest whitepapers on SOA, Application Grid, Enterprise Management and Database

Upcoming Industry Events
  • No upcoming events available
CIO industry insight podcast #11: Brad Howarth talks about the future of broadband
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Get a job Careerone