Please wait while the page is being loaded Skip this advertisement >
Saturday | 22 November, 2008
CIO
CSO: Regrettable Veto
Are there circumstances where a security veto should be wielded? And what are the hidden costs of a security veto

No CSO has "veto power" explicitly stated in his job description. But security is one of the few things other than money that can bring a project to a screeching halt.

Are there circumstances where a security veto should be wielded? And what are the hidden costs of a security veto?

Clearly there are circumstances where security overrides business utility: "No, you can't load 200,000 of our customers' credit cards onto your son's iPod for testing purposes!" Such situations are usually just a matter of policy and compliance.

A real veto is where there is a strong business case for the use of a technology, strategy or application and it is overridden because of an overwhelming risk. And very rarely is there no technology, process or control to mitigate the risk.

Perhaps then, the use of a security veto is an indication of either an insufficient "return on risk" or an insufficient security investment. In the former situation, we are making a wise business decision. In the latter, we are merely hiding a bad decision behind the unassailable excuse of security.

To determine which it is, we have to assess not only the risk and the cost to secure it, but also the opportunity cost — the potential upside of taking the risk.

This evaluation becomes very relevant when we are looking at new, innovative and untested technologies or applications. With new technologies it is hard to evaluate potential risks, and there may not be any well-established controls or countermeasures. It is even harder to foresee the potential upside of new technologies. Technology will be applied in unanticipated ways, yielding unanticipated benefits.

It is precisely these risks that have the potential for the biggest competitive advantage and return. And it seems it is precisely these risks that are subject to veto.

I had the opportunity to benchmark this observation during my recent security research. Fully two-thirds of the responding companies had decided against using a technology or service because of security concerns. Many were forgoing investments in collaborative tools (instant messaging, wikis and so forth).

Our research shows these tools can have a direct impact on top-line performance, when used by sales, for example. Insufficient investment in security can therefore lead to competitive disadvantage. When we wield the security veto, we must consider the cost of a missed opportunity. With sensible, controlled risk comes reward.

More about HIS Limited
Related Features
  • +

    Process Trip 04 February, 2008 13:07:03

    Why Maritz Travel revamped key business processes — and how business and IT came together to make it work
    When Rich Phillips became COO OF Maritz Travel about two and-a-half years ago, he sat down and took a hard look at the big industry picture
  • +

    Ticked Off at Tick the Box Mentality 04 February, 2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    Strategies for Dealing With IT Complexity 24 December, 2007 10:30:47

    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Related Stories
  • +

    Mob wisdom means business 04 January, 2008 07:14:47

    So-called 'crowdsourcing' lets companies create massive focus groups, garner fresh ideas, and even predict the future
    Crowdsourcing, mob wisdom, interactive ideation, artificial AI -- call it what you will, but the idea of tapping external collaborators to develop or enhance products and services is far from revolutionary.
  • +

    Can Macs conquer the enterprise? 11 January, 2008 10:55:53

    The field is wide open for a Macintosh insurrection on the business desktop. It could happen, but probably won't. Here's why.
    If Apple were a football team, the New England Patriots would have had some serious competition this year.
Additional Resources
Featured Whitepaper Sponsors
Market Place
 
Featured Whitepapers

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Chris Hoff on Virtualization and Cloud Computing 20 November, 2008 10:55:00

    Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly.
  • +

    Cybersecurity is focus of new start-up incubator 20 November, 2008 07:19:00

    Texas uni announces the Institute for Cyber Security.
    The University of Texas at San Antonio Tuesday announced a technology incubator aimed at fostering IT security-based start-ups within the state.
  • +

    Dilip Sarangan on Physical Security M&A 20 November, 2008 11:18:00

    Dilip Sarangan tracks physical security companies for Frost & Sullivan. He expects the industry's "need to have" products to weather the economic storm well, with the big players (now including IBM and Cisco) looking for value-priced acquisitions.
  • +

    International Challenges in PCI Security 20 November, 2008 09:15:00

    In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective.
  • +

    PCI council sharpens oversight of security auditors 19 November, 2008 10:53:00

    Quality assurance plan targets security assessors and scanning vendors
    The PCI Security Standards Council Monday unveiled a plan to sharpen oversight of the hundreds of security-service providers now authorized to evaluate merchant networks under the organization's Payment Card Industry data standards.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Best Practice in Building an Integrated Information Management Strategy

Discover the business value that creating an integrated information platform can bring. Learn how to provide consistent, accurate information to all stakeholders within your business network. Integrate vital data from disparate sources and deliver a trusted information foundation. Read on to uncover the stepping-stones to your new information management strategy.