- When somebody asks you about the goals of a project, answer goals.
- When somebody asks you about the ethics of a project, answer ethics.
- When somebody asks you about the management of a project, answer management.
- When somebody asks you about the deadlines of a project, answer deadlines.
- When somebody asks you about the means or technology of a project, answer means or technology.
Wednesday, June 23, 2010
Leadership learning 1
Wisdom being to recognize wisdom when you hear or see it, let me put it down what I heard from a management old-timer :
Tags:
ciso'ing,
leadership insights
Thursday, May 27, 2010
Notes: Profile for a CISO?
I was at the 4th International Forum on Cybercriminality and there was a conference about CISOs' professional profile.
I just took a few notes and, seemingly, there are three major kinds of personalities for a CISO:
I was also interested in this definition they gave: "The CISO is the one who defends the ITsec budget."
Finally, they described an evolution in the profile of CISOs:
I just took a few notes and, seemingly, there are three major kinds of personalities for a CISO:
- The pilot,
- The architect, IT urbanist,
- The administrator.
I was also interested in this definition they gave: "The CISO is the one who defends the ITsec budget."
Finally, they described an evolution in the profile of CISOs:
- In the 1990's, people became CISO by opportunism,
- In the 2000's, people became CISO through competition,
- In the 2010's, people are becoming CISO by choice or by vocation.
Wednesday, May 26, 2010
Monthly ITsec Leadership Quotes and Articles
- Everything I Need to Know About Leadership I Learned as a Patrol Leader on the TaoSecurity blog.
- Forget ROI and Risk. Consider Competitive Advantage also on the TaoSecurity blog.
Let me add a number 4: "Boss-centric approach" (whether your boss is CIO, CEO or CSO...)
Security person: Hello boss. We need to implement our security program because it fits perfectly in your strategic points 1, 2 and 3 and helps you show just how well you deliver - Antons Chuvakin's My Best PCI DSS Presentation EVER! on the Security Warrior blog, contains good pieces to address communication with non-security people.
- Survey about ITsec maturity criteria: What should be audited in order to evaluate an ITsec maturity level? Page 26 to 28 in this [FR] PDF, on the site Les Assises de la Sécurité et des Systèmes d'Information.
- Joking as a way to get people closer to security: The BOFH-like excuses.
I'm getting more and more convinced that the leadership style of Bruce Schneier is what made him so popular. There is more of personality than leadership in his case. In fact, my way to answer about "the mixture of security and feelings" is very close to his. Two examples:
A few quotes heard at the 4th International Forum on Cybercriminality :
- "Nowadays you learn more about someone from Facebook than from Edvige." (Edvige is a nominative information file used by the French police.)
- "The problem is not adapting to the digital world, it's adapting to the border-less world."
- "In healthcare, IT security is a deontological requirement."
- "Estonia is ahead of us [ahead of France regarding ITsec]."
Oh, by the way, I finally got a hint on why do they all emphasize on "Information Security" rather than "IT Security": I think it's because they want people to understand that it's not an IT-only problematic.
Thursday, May 13, 2010
Transparency the Next Big Topic? I Don't Think So :-(
Here is a recent Bruce Schneier interview "If you don't understand the people you'll never understand security, says Schneier". I really appreciate Bruce Schneier for his stick_to_the_fact and be_smart_not_an_automate approaches.
However, when he says during that interview that the next big topic for security will be transparency, I think it's more of a wishful thinking. I can see three main reasons why the move to transparency will be very slow:
However, when he says during that interview that the next big topic for security will be transparency, I think it's more of a wishful thinking. I can see three main reasons why the move to transparency will be very slow:
- Good transparency requires transparency from both the vendor and the buyer. I think the buyer will never see the point of publishing data about (in)security. Even if that's more or less a kind of corporate social responsibility...
- Some major players among vendors and some managers in whatever buyer's hierarchy do not want to play the game by the rules. They prefer it the way it is, especially if they have a good ROI/good wages and not too much stress. So, unless there is some interventionism, I think they will do their best to slow the move.
- If you're going to publish things transparently, you might think of it as a possible bad advertisement for your company. And the weak point is: most companies, buyers or vendors, do not know where they stand among peers on the criteria of IT security. So they will not want to make the first move and risk publishing what might be seen as bad results.
Tags:
open VS closed,
security insights
Wednesday, April 28, 2010
Fun fact: Google search ratios about problems, by OS
Search pattern | Number of results | Ratio of "problems" |
| "windows 98" | 21,900,000 | |
| "windows 98" problem | 6,770,000 | 30.91% |
| "windows millenium" | 291,000 | |
| "windows millenium" problem | 77,500 | 26.63% |
| "windows xp" | 124,000,000 | |
| "windows xp" problem | 61,400,000 | 49.52% |
| "windows vista" | 80,900,000 | |
| "windows vista" problem | 88,200,000 | 109.02% |
| "windows seven" | 2,900,000 | |
| "windows seven" problem | 551,000 | 19.00% |
Saturday, April 24, 2010
Monthly ITsec Leadership Quotes and Articles
- Influential Information Security Leader on the Identity Theft Awareness site.
- The oldie but still goodie An Absence of Leadership on the official site of Geekonomics.
- My excellent colleague Guillaume Deraedt, at a regional chapter of hospital CISOs: "A CISO handles non-conformity", as opposed to the compliance view of handling conformity.
Saturday, April 17, 2010
Altering the philosophy of this blog
I have long felt that responsibility in information security was a hard management job.
I have always known, through personal temper, that leadership is an asset in every management position.
Yet it never appeared to me until a few semesters ago how much responsibility in information security was a job that required, most of all, leadership skills. For this reason, I have chosen to more regularly publish articles on this site about the leadership of information security, including good readings about it, even uncommented.
Among the reasons that conspired to enhance my point of view, here are a few:
So now comes the time when I emphasize on leadership.
Comments, praises and amazements welcome.
I have always known, through personal temper, that leadership is an asset in every management position.
Yet it never appeared to me until a few semesters ago how much responsibility in information security was a job that required, most of all, leadership skills. For this reason, I have chosen to more regularly publish articles on this site about the leadership of information security, including good readings about it, even uncommented.
Among the reasons that conspired to enhance my point of view, here are a few:
- Working as responsible in this field for more than two years now.
- Realizing that the job is a drop about team management, a bucket about upwards management and an ocean about transversal and stakeholders' management.
- Realizing that security is a lot about conceptions and misconceptions, and that vendors are better at it than internal managers of any company. And that reacting to this situation takes a lot of communication towards the teams.
- Having Anton Chuvakin summarize one of my articles by naming my job "expert in security leadership", which made me think a lot.
- Reading books like "Geekonomics", by David Rice or "The CISO function [FR]", by Bernard Foray.
- Seeing that everyone is capable of designing a highly sophisticated security framework in his head, but less often implement it.
- Reading a lot of blog articles from security experts, and writing a few, complaining about people's behaviour and misconceptions and calling for help, for people to change.
So now comes the time when I emphasize on leadership.
Comments, praises and amazements welcome.
Subscribe to:
Posts (Atom)