Vulnerabilities / Threats
10/31/2013
04:56 AM
Tim Wilson
Tim Wilson
Quick Hits
50%
50%

Shortage Of Women Hurting IT Security Industry, Study Finds

(ISC)2 survey indicates that women have the skills and attitudes most needed in infosec

Today's information security teams increasingly need to improve their communications with other groups, align their activities more closely with business objectives, and excel at a variety of diverse tasks, industry experts say. And a new study suggests that these skills and attributes are most common among the industry's smallest minority of professionals: women.

Women represent about 11 percent of the current IT security workforce, according to "Agents of Change: Women in the Information Security Profession" (PDF), a new report written by Frost & Sullivan and published by the (ISC)2 security professionals' association. Yet women's strongest skill sets are the very skill sets that are in short supply across the industry, the report suggests.

"Security is becoming less about technology and more about people -- understanding their behavior and protecting users as they do their work," says Julie Peeler, director of the (ISC)2 Foundation. "The study shows that women tend to value skills such as communication and education -- the skills that are currently in short supply."

"The report data indicates that the perspectives of women offer viewpoints needed to elevate the security industry to the next level," adds Michael Suby, author of the report and vice president of research at Frost & Sullivan.

Survey respondents were divided into two job title categories: Leaders and Doers. The Leaders (3,466 respondents) category included job titles such as executives, managers, and strategic advisers. Doers (2,348 respondents) included respondents with job titles such as security analysts and compliance auditors.

In the Leaders category, more women (34 percent) were in consultant and adviser job titles than men (26 percent), and more than twice as many men as women were network security or software architects. In the Doers category, 38 percent of women cited security analyst as their job titles, versus 27 percent of men. A higher proportion of men held security engineer and network administrator job titles.

"The 2013 Global Information Security Workforce Study identified 'security analyst' as the number one most needed position in the information security industry, leading the way for a strong female presence in the future," the report says.

IT security has traditionally been dominated by males who study computer sciences in school and are strong in technology, Peeler observes. But as security practices increase their focus on communication and training, it's possible that women will play a more important role.

"In the past, companies have taken their IT people, who are strong technically, and tried to teach them how to communicate with staff and management," Peeler notes. "But recently, they've begun to discover that it's easier to teach technology to someone who communicates well than it is to teach communication to someone who's basically a technical person."

But getting women into the security profession may not be easy, Peeler says. The percentage of females in the industry has not changed much in the past several years, and there doesn't appear to be a great influx on the horizon.

"More needs to be done in the schools and in business to make security more attractive to women," Peeler says. "Studies show that many females are bored by the idea of working alone in a room with a machine. But as the industry becomes more about people and less about technology, that could change."

"Combating [current] threats requires a community approach to training, and hiring qualified security professionals from a variety of backgrounds," Suby states. "As our research reveals, women leaders are the strongest proponents of security and risk management education and training in the industry. This type of mentality is crucial to building standards in the industry and echoes the report's findings that women are indeed, 'agents of change' in the future of information security."

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jobewan
50%
50%
jobewan,
User Rank: Apprentice
11/7/2013 | 9:37:12 PM
re: Shortage Of Women Hurting IT Security Industry, Study Finds
"The study shows that women tend to value skills such as communication and education -- the skills that are currently in short supply."

The above statement is open ended to the point of being non sequitur. Valuing a concept and being good at same, are also two very separate concerns.

The reason information security has really always been about people, is that people are the greatest threat to information security; a position borne out by significant empirical data.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7402
Published: 2014-12-17
Multiple unspecified vulnerabilities in request.c in c-icap 0.2.x allow remote attackers to cause a denial of service (crash) via a crafted ICAP request.

CVE-2014-5437
Published: 2014-12-17
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php,...

CVE-2014-5438
Published: 2014-12-17
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.

CVE-2014-7170
Published: 2014-12-17
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

CVE-2014-7285
Published: 2014-12-17
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.