Security 2.0. That may not be an official moniker for the state of security, but with Web 2.0 and Cloud 2, perhaps it should be. Indeed, the role of the chief security officer has evolved — and expanded — in the past 10 years. Even in the past year, policy, process and technology look different.
A security professional needs to embrace the change from controlling what devices employees use, how the devices connect to the corporate network, and what applications are allowed. That leads to a new approach that most organizations are moving toward to provide the capability for employees to connect to the corporate data from anywhere and any device.
For example, technology allows employees to easily connect their work and home lives through social media, blurring the line between personal and work. Another shift that a CSO must embrace is the move away from implementing controls to protect data, to developing ways to trust cloud vendors as data moves out of their control.
Are CSOs Losing Control?
“Many CSOs are struggling with the increased use of personal devices like iPad, iPhones, Droids, etc. Some still believe that they can control what the users can and cannot use in their corporate environments,” said Randy Barr, CSO at Qualys. “Unfortunately, they have not realized that they are slowly losing the ability to control what their employees can and cannot use. Users today have more knowledge about supporting their devices compared to users 10 years ago.”
Access to the Internet through employees’ personal devices is much faster. Organizations that block tools like instant-messaging services and sites like Facebook and Twitter are finding these are now easily accessible through personal devices like iPhones, iPads and Android-powered devices, Barr noted.
Tools available as a service are also more accessible to employees than in the past….