Miscellaneous

Business Blogs - Blog Rankings

« Leadership Principle #3 - Coin Catch Phrases, Say Them Over & Over | Main | Healthcare Industry Group Publishes Certifiable Security Framework »

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a01156fbeecf2970c0120a52bdb1d970b

Listed below are links to weblogs that reference Take the "T" out of Information Security!:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

I prefer the military nomenclature of Information Assurance. I have carried it over to the commercial world and make sure all my security types carry that title now. I like the definition and what it means:

Assurance - a positive declaration intended to give confidence; a promise

My teams positively declare with confidence that the information of our systems is assured. It carries some weight and responsibility on their parts.

Hi Nicholas,

Thanks for the comments.

I too like Information Assurance. Coincidently, I served in the 101st Airborne Division right out of school. At the time, I don't believe the US Army had adopted the use of "Information Assurance", though I could be wrong. However, they certainly have since then.

I took a similar approach in rebranding in my last role at Lilly by branding our group "Information Risk". The idea being to recognize information security trends, such as:

- Collaborative Environments such as Cloud Computing, that are forcing companies to make trade offs in controls they simply haven't had to make in the past.
- Proliferation in Laws and Regulations that are driving large companies to establish cross-functional governance to rationalize and prioritize control investments.
- And tied directly to the second point, the emergence of "Enterprise Risk Management" capabilities that are increasingly being tied to both Corporate Compliance functions as well as Corporate Security functions.

In fact, my division's title was "Enterprise Information Risk and Compliance". Of course given that no two organizations are exactly alike, I'm sure that there is no exact right way of branding. For example, our group was responsible for IT QMS strategy, IT Policies and Procedures, and Information Standards that included Information Security. However, we weren't responsible for operational security.

In the end, I think we both had the same intent on taking the "T" out of Information Security. Thanks for the comments!


Mark Brooks


Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

Connect w/Mark