|
|
|
Morrow converges enterprise risk |
By Rhianna Daniels - 04.2008
|
|
DALLAS-At February's TechSec Solutions conference, Dave Morrow, chief security and privacy officer for EDS, moved away from the technical piece of convergence for an hour and focused on a broader view - approached from an enterprise risk management perspective. EDS, which is the second largest IT outsourcing firm in the world, merged its IT and physical security departments in 2005 under Morrow's leadership and he presented the benefits and challenges associated with this transition in his closing keynote address. The key is "looking at an organization as an enterprise," but that can be difficult in a business that has traditionally viewed physical and IT security as siloed departments, which was the case previously at EDS. "There was little in common between these two," Morrow said. "They kind of hated each other." Morrow's first course of action was to get management to understand that the entire security team must both protect and enable the business. "We took a look at what we were doing as a department and if these things were not benefiting the business, we weren't going to do it anymore," he said. Morrow is not just working on this view of convergence at his organization; he is also working with the Alliance for Enterprise Security Risk Management, a group that was formed by ASIS International, ISACA and the Information Systems Security Association and brought together global security professionals with broad security backgrounds and skills to address the increase and complexity of security-related risks to international commerce from terrorism, cyber attacks, Internet viruses, theft, fraud, extortion and other threats. AESRM released a report titled, "The Convergence of Physical and Information Security in the Context of Enterprise Risk Management" in 2007 that looks at the benefit of a converged view of security in managing enterprise risk. But there are challenges. When Morrow began merging IT and physical security operations, it was difficult to get both departments to think about the other's main concerns. For example, he asked the physical security department to determine the number of laptops that had been stolen in the last month. The personnel came up with the price per laptop and then multiplied the cost by the number of laptops lost. But what about the value of the data stored on the laptops? "The departments think differently," he said. "You need to get them using their skills, but thinking on the same level." Morrow has seen the gap narrow in the past three years, especially when one of his leaders, "a card-carrying CPP" recently earned his CISM certification. "He is proof that it is possible to bring these groups together, they just need to speak each other's language," he said. To see video of Morrow's closing presentation, please visit www.securitydirectornews.com/index.php?p=blogs. SDN
|
()
|
|
|
|
|
SDN News Info Center |
|
|
SOURCE BOOKS
|
|
2009 Systems Integration Source Book |
|
The value of the systems integrator..p3 What to consider when choosing a service provider..p4 Our list of systems integrators..p6 |
|
2009 IP Technology White Paper |
|
A virtual roundtable p3... In IP system that is and isn't p.4... It's all HD to me p.6... Yet more convergence p.8... Standard play p.10 |
|
2008 Access Control & Biometrics |
|
Increased security, convenience and reduced costs boost biometric market...p3 'Finally starting to see tangible results'...p4 Access control & biometrics buyer's guide...p6 |
|
Systems Integration Source Book |
|
Security directors rely on integration firms to help merge technology, people and processes |
|
|
CALENDAR
|
|
| 6-8 Physical security: advanced applications and technology | | ASIS International. St. Louis. For more information, visit www.asisonline.org | | 6-8 Physical security: advanced applications and technology | | ASIS International. St. Louis, Mo. For more information, visit www.asisonline.org. | | 13-14 Executive Protection | | ASIS International. Chicago, Ill. For more information, visit www.asisonline.org. | | 14-16 Axis 3-day Fundamentals | | Kansas City, MO | | 20-22 National Association of School Safety and Law Enforcement Officers | | 40th Anniversary Conference, Astor Crown Plaza, New Orleans. For more information, visit www.nassleo.org. | | 21-23 Axis 3-day Fundamentals | | Chelmsford, MA | | 22-24 American Association of Port Authorities Port Security Seminar and Expo | | Houston, Texas. For more information, visit www.aapa-ports.org. | | 26-29 National Food Service Security Council | | 30th Annual Conference & Exposition. Sheraton New Orleans Hotel, La. For more information, visit www.nfssconline.org. | | 28-30 Axis 3-day Fundamentals | | Houston, TX | |
| 10-13 Axis 3-day Fundamentals | | Irvine, CA | | 18-20 Axis 3-day Fundamentals | | Chelmsford, MA | | 25-27 Axis 3-day Fundamentals | | Calgary, Alberta | |
| 1-3 Axis 3-day Fundamentals | | Chelmsford, MA | | 15-17 Axis 3-day Fundamentals | | Newark, NJ | | 18-19 ASIS CPP, PCI, and PSP Classroom Reviews | ASIS CPP, PCI, and PSP Classroom Reviews
Anaheim Marriott
Anaheim, CA
For more information, visit: www.asisonline.org/certification/exam_reviews.xml
| | 21-24 ASIS International 55th Annual Seminar & Exhibits | | Anaheim, Calif. For more information, visit www.asisonline.org. | | 22-24 Axis 3-day Fundamentals | | Louisville, KY | |
| 3-7 International Association of Chiefs of Police Annual Conference | Denver, Colo. For more information, visit www.theiacpconference.org.
| | 4-7 American Public Transportation Association, Annual Meeting | | Orlando, Fla. For more information visit, www.apta.com/conferences_calendar/#other | |
| 17-19 Global Gaming Expo | | Las Vegas Convention Center, Las Vegas. For more information, visit www.globalgamingexpo.com. | | 30-4 Wharton/ASIS Program for Security Executives | The Wharton School of Business
Philadelphia, PA
For more information, visit: www.asisonline.org/wharton/noframe/index.htm | |
| 1-3 International FAA Runway Safety Summit | | Hosted by the Federal Aviation Administration and the American Association of Airport Executives. Omni Shoreham Hotel, Washington, D.C. For more information, visit faaintlrunwaysafetysummit@aaae.org | | 7-8 Executive Protection | | ASIS International. Washington, D.C. For more information, visit www.asisonline.org. | | 10-11 American Association of Airport Executives, Security Summit | Washington, DC. For more information visit, http://events.aaae.org/sites/081204/
| |
| 1-5 Wharton/ASIS Program for Security Executives | The Wharton School of Business
Philadelphia, PA
For more information, visit: www.asisonline.org/wharton/noframe/index.htm | |
|
|
|
|
|
|