author photo
By Mike Gentile
Wed | Jul 24, 2013 | 9:08 AM PDT

This series will explore 5 tips to build a sustainable, repeatable & effective C+ security effort. One that can pass security audits, comply with regulations, while still maintaining a strong dose of practicality. Time to go from F to C+, baby! Tip #4: Being Repeatable and Consistent is the Life Blood of the C+ Student The good thing about being a C+ student in security is that you will probably be much more effective in getting stuff done as well as cost effective at doing it; both in implementation cost and impacts on the business. The problem with this approach though is that you do not have much room for failure when you make mistakes. With an A+ approach, a couple mistakes will still leave you with a B. With a C+ approach a couple mistakes and you are in the land of D, or not compliant in regulation speak. Obviously, this is going to lead to problems. So the key when taking a more average approach is to make sure that you implement systems that, though average in implementation, are an A+ in terms of quality and repeatability. For example, you may be building an economy car instead of a luxury one, but make sure it is a Toyota instead of a Hugo in terms of quality.

As always, please provide your feedback to Mike.Gentile@delphiis.com or @delphiisCTO on Twitter; I always read them.

Read Part 1: http://www.secureworldexpo.com/building-c-security-effort-%E2%80%93-5-tips-achieve-what-your-execs-want-your-business-needs-making-security

Read Part 2: http://www.secureworldexpo.com/building-c-security-effort-%E2%80%93-5-tips-achieve-what-your-execs-want-your-business-needs-you-only-need

Read Part 3: http://www.secureworldexpo.com/building-c-security-effort-5-tips-achieve-what-your-execs-want-your-business-needs-do-not-only

Read Part 4: http://www.secureworldexpo.com/building-c-security-effort-5-tips-achieve-what-your-execs-want-your-business-needs-don%E2%80%99t-ask-just

Tags: CISO / CSO,
Comments