(ISC)² Twitter Updates

  • (ISC)² Twitter Updates

    About the
    (ISC)² Blog

    • (ISC)² believes in the importance of open dialogue and collaboration, between both (ISC)², its certified members and members of business and society.

      (ISC)² established this blog to provide a voice to its certified members, who have significant knowledge and valuable insights to share that can benefit the information security industry, the people in it and the public at large.

      The postings on this site are the author's own and don't necessarily represent
      (ISC)²'s positions, strategies or opinions. (ISC)² does not control, monitor, or endorse any links provided in this blog and makes no warranty or statement regarding the content on any linked website.

      Those who post comments to blogs should ensure their comments are focused on the topic at hand. (ISC)² reserves the right to remove any post or comment from this site.

      Should you find objectionable content in this blog, please notify us as soon as possible at blog@isc2.org.

      Please click here for FAQs.

      Please click here for the Blog guidelines.

    « Data leakage in social media | Main | Habitual security - the way we do things »

    07 June 2012

    Comments

    A fair summary if you are head honcho in a small to medium sized organisation.

    However as an infosec professional in a large corporation the sources of stress I see most relate to:
    Constant demands to respond to audits
    Constant demands to report to management/governance groups
    Lack of funding
    Confusing rules and channels when working with comms teams
    Conflicting role mandates between security/infrastructure/HR/1st,2nd,3rd line risk

    Most (ISC)2 members could probably do a good job given a small enough organisation and clear enough mandate. But stress too can be caused by a feeling of a lack of control and support in ones role.

    Great post on the challenges security professional face. Tom is spot on when he says "Your first step on the path to taking control of the system is to perform a full and thorough information security audit of all software and hardware assets." For insight on how one government agency was able to gain visibility into and the required control over every single endpoint on its network – servers, laptops, desktops, etc, check out http://bit.ly/Mrztig.

    The comments to this entry are closed.

    Recent Contributors

    Past Contributors