Click to Tweet: Symantec helps CISOs speak language of business: http://bit.ly/wyg5eV
Security threats and risk management are becoming part of boardroom-level discussions. A January 2012 study conducted by Forrester Consulting on behalf of Symantec found:
70 percent of security decision makers reported increased executive awareness of IT security as a direct result of recent high profile attacks and data breaches
When asked what changes to their IT risk program would have the most positive impact on their business counterpart relationships, 47percent indicated the improved ability to communicate the value of security and risk management in business terms
More than 40 percent called out the need for more timely and accurate data or more frequent reporting of risk and compliance
Symantec Control Compliance Suite Risk Manager module will allow security leaders to create a targeted view of IT risk as it relates to a specific business process, group or function. Instead of sending business unit owners detailed reports on outstanding configuration or vulnerability issues, they will be able to illustrate how these issues are causing unacceptably high risk to the company’s online e-commerce site, transaction processing system or other key business process. Translating technical IT issues into business risk terms that can be more easily understood helps drive greater awareness, accountability and action.
The solution will facilitate more effective communication around IT risk by allowing security leaders to customize dashboards with audience-specific risk metrics.
Executive-level dashboards can illustrate high-level metrics, such as risk by business unit, or risk scores for mission-critical business processes.
Security operations dashboards can drill down to examine technical details behind these risk scores.
Dashboards for IT operations can outline detailed remediation plans and monitor risk reduction over time as scheduled remediation activities take place.
These different dashboard views provide business stakeholders with the information they need to make better decisions around IT risk, while ensuring that security and IT operations teams are more closely aligned on what needs to be done to reduce the most critical risks to the business.
Symantec Control Compliance Suite will feature a flexible, scalable data framework which is critical to providing a rich data-driven view to multiple audiences. This framework greatly simplifies the process of bringing together and “normalizing” information from multiple different sources, so that it can be viewed in a common format. The suite brings together automated, technical assessment information with manual data inputs and procedural assessment information. It combines all of this with additional data from other Symantec and non-Symantec solutions, providing a rich set of information available for better analysis and decision making. The result is a truly multi-dimensional view of the IT risks associated with any given business process, group or function.
Quotes
“The ability to move beyond the traditional role of technical expert and become a business risk advisor is critical to the success of today’s IT security leaders,”said Art Gilliland, senior vice president, Information Security Group, Symantec. “Symantec’s next generation IT GRC solution will empower information security leaders to drive real change and accountability with their business counterparts at a time when security threats are becoming boardroom level discussions.”
“When you are called before senior executives of the business to talk about IT risks, you better have sound metrics behind you. Gathering this information and effectively communicating it to business stakeholders is one of the biggest challenges we face today. With Control Compliance Suite Risk Manager, Symantec is providing a powerful tool to help address this challenge,” said Tim Stanley, director of information and infrastructure security, Waste Management, Inc.
“We are seeing a growing number of CISOs being asked to provide a business-centric perspective of IT risk that executives and line-of-business managers can understand and act upon. Meeting this need requires a strong focus on the intersection of risk management and IT-based business processes,” said Jon Oltsik, senior principal analyst, Enterprise Strategy Group.
Availability
Symantec Control Compliance Suite 11 is expected to be available by early summer 2012.
Resources
Press Kit Blog: CISOs: Make the Most of Your Time in the Boardroom White Paper: Strengthening Ties Between IT and the Business Infographic: Changing Role of the CISO SlideShare: Symantec Control Compliance Suite 11 Podcast: Symantec Control Compliance Suite 11 CCS Risk Manager Data Sheet Control Compliance Suite Brochure Control Compliance Suite Video
Connect with Symantec
Follow Symantec on Twitter Join Symantec on Facebook Subscribe to Symantec News RSS Feed View Symantec’s SlideShare Channel Visit Symantec Connect Business Community
About Symantec
Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
How To Boost Security Via FFIEC Compliance
With just a smartphone, users can conduct nearly all their banking business at any time of the day or night. However, all this flexibility and convenience opens up new avenues for fraud and cybercrime. Guidelines laid out by the FFIEC several years ago predate many of the capabilities-and vulnerabilities-that are in place today. In this report, we examine the latest guidelines and provide advice on how you can extend the work done to comply with FFIEC guidelines to strengthen your organization's overall security posture and keep customers and their data safe.
Keeping Compliance In Check
Configuration mistakes, access control gaffes, poor documentation--it doesn?t take much for a compliance audit to go all wrong. In this special retrospective of recent news coverage, Dark Reading takes a look at the costs, common missteps and best practices for compliance, as well as the day the Internet nearly went dark due to the threat of new regulations.
FISMA Lifts All Compliance Boats
FISMA may not be on your radar now, but it likely will be at some point. Geared specifically toward the federal government and its affiliate agencies and third parties, FISMA is a very specific set of requirements aimed at establishing and maintaining at least a baseline level of computer and network security. FISMA requires unique categorization and classification of information assets, not to mention a boatload of documentation to prove compliance. But once your organization achieves FISMA compliance, it will likely be compliant with just about every security mandate out there.
Other reports from the Compliance Tech Center:
| Sponsored by: |
Log Management in 2012 and Beyond
2012 brings interesting changes to the log management world. Now, more than ever, it is critical to understand the impact to your log infrastructure and the solutions that will better prepare you to manage your security posture.
SANS Log Management Survey Report
Organizations are increasingly dependent on log management to support core business functions, including cost management, service level and line-of-business application monitoring, as well as traditional IT- and security-focused activities.
Cut the Time and Effort of Troubleshooting and Reporting
Organizations generate millions of logs a day and struggle with centralized collection, storage and analysis of those logs. ArcSight Logger is a universal log management solution that unifies searching, reporting, alerting and analysis across any type of IT data. It consolidates silos of logs into a single indexed repository for fast detection and mitigation of operational issues.
Get Turnkey and Automated PCI Compliance
PCI compliance monitoring is seamless with the self-contained ArcSight PCI Logger solution for log collection, storage and analysis. No database administration expertise is required and a web-based interface simplifies deployment and ongoing management.
Swiss Bank Meets Compliance Requirements and Protects Customer Data
Due to long-term data retention requirements, Swiss bank EFG needed a cost-effective way to collect, secure and store audit-quality log data in an easily accessible log repository. ArcSight Logger helps EFG meet key requirements of Switzerland?s banking laws fast and cost-effectively.
MORE NEWSFEED >>>