Vulnerabilities / Threats
10/31/2013
04:56 AM
Tim Wilson
Tim Wilson
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%

Shortage Of Women Hurting IT Security Industry, Study Finds

(ISC)2 survey indicates that women have the skills and attitudes most needed in infosec

Today's information security teams increasingly need to improve their communications with other groups, align their activities more closely with business objectives, and excel at a variety of diverse tasks, industry experts say. And a new study suggests that these skills and attributes are most common among the industry's smallest minority of professionals: women.

Women represent about 11 percent of the current IT security workforce, according to "Agents of Change: Women in the Information Security Profession" (PDF), a new report written by Frost & Sullivan and published by the (ISC)2 security professionals' association. Yet women's strongest skill sets are the very skill sets that are in short supply across the industry, the report suggests.

"Security is becoming less about technology and more about people -- understanding their behavior and protecting users as they do their work," says Julie Peeler, director of the (ISC)2 Foundation. "The study shows that women tend to value skills such as communication and education -- the skills that are currently in short supply."

"The report data indicates that the perspectives of women offer viewpoints needed to elevate the security industry to the next level," adds Michael Suby, author of the report and vice president of research at Frost & Sullivan.

Survey respondents were divided into two job title categories: Leaders and Doers. The Leaders (3,466 respondents) category included job titles such as executives, managers, and strategic advisers. Doers (2,348 respondents) included respondents with job titles such as security analysts and compliance auditors.

In the Leaders category, more women (34 percent) were in consultant and adviser job titles than men (26 percent), and more than twice as many men as women were network security or software architects. In the Doers category, 38 percent of women cited security analyst as their job titles, versus 27 percent of men. A higher proportion of men held security engineer and network administrator job titles.

"The 2013 Global Information Security Workforce Study identified 'security analyst' as the number one most needed position in the information security industry, leading the way for a strong female presence in the future," the report says.

IT security has traditionally been dominated by males who study computer sciences in school and are strong in technology, Peeler observes. But as security practices increase their focus on communication and training, it's possible that women will play a more important role.

"In the past, companies have taken their IT people, who are strong technically, and tried to teach them how to communicate with staff and management," Peeler notes. "But recently, they've begun to discover that it's easier to teach technology to someone who communicates well than it is to teach communication to someone who's basically a technical person."

But getting women into the security profession may not be easy, Peeler says. The percentage of females in the industry has not changed much in the past several years, and there doesn't appear to be a great influx on the horizon.

"More needs to be done in the schools and in business to make security more attractive to women," Peeler says. "Studies show that many females are bored by the idea of working alone in a room with a machine. But as the industry becomes more about people and less about technology, that could change."

"Combating [current] threats requires a community approach to training, and hiring qualified security professionals from a variety of backgrounds," Suby states. "As our research reveals, women leaders are the strongest proponents of security and risk management education and training in the industry. This type of mentality is crucial to building standards in the industry and echoes the report's findings that women are indeed, 'agents of change' in the future of information security."

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jobewan
50%
50%
jobewan,
User Rank: Apprentice
11/7/2013 | 9:37:12 PM
re: Shortage Of Women Hurting IT Security Industry, Study Finds
"The study shows that women tend to value skills such as communication and education -- the skills that are currently in short supply."

The above statement is open ended to the point of being non sequitur. Valuing a concept and being good at same, are also two very separate concerns.

The reason information security has really always been about people, is that people are the greatest threat to information security; a position borne out by significant empirical data.
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7298
Published: 2014-10-24
adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privileges by leveraging improperly protected setuid functionality.

CVE-2014-8346
Published: 2014-10-24
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic.

CVE-2014-0619
Published: 2014-10-23
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

CVE-2014-2230
Published: 2014-10-23
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

CVE-2014-7281
Published: 2014-10-23
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.