Andrew Rose serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
New Research: Organizational Challenges
Posted by Andrew Rose on January 27, 2012
- 278 Recommendations
- 0 comments
I was reading an article recently which outlined the different agencies employed within the United Kingdom to protect against cyber-threats. Not including the armed forces, who would have specialist roles to play in any particular cyber-threat scenario, it transpires that there are 18(!) different players covering this space, each with overlapping strategies, policies and expenditure. The formal report, from the UK Government’s Intelligence & Security Committee, was wonderfully understated, speaking of "confusion and duplication of effort".
Such difficulties bring to mind the challenges we face in our global organizations, which are often made up from different corporate entities. Similar issues can happen to our security management functions - we overlap, overspend and contradict – all to the detriment of the enterprise as a whole. Managing a global information security function in an optimal manner is no easy task; it takes careful planning, an understanding of essential roles & responsibilities and the ability to manage some elements remotely.
I’ve recently published two papers relating to these very topics. If you are considering a reorganization, or just interested in what top performing security organizations look like right now, check out these links:
- Define A Road Map To Accelerate The Organizational Maturity Of Your Security Program
- Build A Strategic Security Program And Organization
Categories:
search forrester's blogs
Analyst Blogs
- Andras Cser (31)
- Andrew Rose (19)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (21)
- Eve Maler (21)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Masami Kashiwagi (1)
- Nick Hayes (5)
- Rick Holland (21)
- Stephanie Balaouras (50)
Top Categories
- CISO (3)
- cloud (2)
- Cyberinsurance (2)
- data security (2)
- Risk Management (2)
- Security & Risk (2)
- 2013 (1)
- access control (1)
- Application Development (1)
- Asia Pacific (1)
- See all
Archives
- June 2013 (2)
- January 2013 (2)
- November 2012 (1)
- August 2012 (1)
- July 2012 (1)
- May 2012 (1)
- March 2012 (3)
- February 2012 (2)
- January 2012 (1)
- December 2011 (2)
- October 2011 (1)
- July 2011 (2)