How to make business managers responsible for security

How to make business managers responsible for security

It's often said but rarely followed: The security manager isn't accountable for security; rather, he is accountable for making sure everyone else in the company is accountable for security. In this presentation, Tom Doughty, vice president of information systems at Prudential Financial, shows you the most effective ways your security team can motivate -- rather than mandate -- security sensitivity in an organization's various lines of business. Doughty shares Prudential Financial's philosophy that final accountability for maintaining secure business practices belongs to the business stakeholders. You see how the organization has moved toward functional-level execution of enterprise-level control initiatives. Plus, you learn how security can be baked into business processes without incurring unwanted costs, project delays or headaches.

Download this presentation for a solid understanding of:

      Requires Free Membership to View

      SearchFinancialSecurity.com members gain immediate and unlimited access to in-depth technical advice, strategies, and expert guides for securing data in high-risk financial environments. Join me on SearchFinancialSecurity.com today!

      Michael S. Mimoso, Editorial Director

      By submitting your registration information to SearchFinancialSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchFinancialSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

    • MORE INFORMATION

      Read more tips and expert advice on creating a corporate culture of security

      View more presentations from some of the industry's foremost security practitioners

      Learn more about Information Security Decisions

    • The keys to "backward planning" for security, i.e. how security professionals can advocate for their interests in terms management understands
    • Why fluid controls for fluid stakeholder objectives drive business management ownership
    • The difference between belief-driven execution and rule-driven execution as a control multiplier
    • The value of business management and staff as intelligence gatherers for your security program
    • The key difference in stakeholders' perspective of security programs versus technical risk management programs
    • Why C-level buy-in is not enough

      Download this presentation


    This was first published in March 2008

    Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.