A new, pragmatic approach to security - is it the future of security?
New times call for new ideas. In security we have seen a revolution over the past few years in the depth and breadth of security solutions that are available to the security administrator and CSO. However, all of this new technology and the methods of securing our businesses and data have not left us any safer or more secure. The reasons for this are many. Some are, the increased sophistication of the bad guys tools, the monetary reward to the hacker, the lack of secure software development, mono-cultural computing environments, etc. So throwing more technology and dollars at the problem is not the solution. What is the professional security person to do? The answer comes from our friend Mike Rothman. Mike has had a vision of writing a book and developing a community that offers the over-stressed security professional a new way of dealing with the problems. A blueprint for success in security. A realistic and holistic model to succeed in these tough new times. In short a pragmatic methodology to becoming a successful security manager and a happier person. He calls the book and the soon to be launched community the Pragmatic CSO. Don't let the CSO part fool you. If you are in any way, shape or form responsible for security as part of your job or want to learn what to do to get a handle on a near impossible task, this book and the content to follow on the web site is for you. At $97 dollars for the PDF version it is a steal and I would not waste any time before buying it.
I was lucky enough to be given an advance copy of the book by Mike last month. Truthfully, I was going to take a look at it as a courtesy to Mike, but did not relish the thought of reading yet another boring business book. I was hooked in the first chapter. The fictional Mike attends his first 12 step "security anonymous" program. His story is one that is all too familiar to many of us in the security field. Despite the hard work, the never ending flow of money out the door and the best of intentions, it is just not working. The security is not there, the boss doesn't appreciate the problems or the amount of effort that goes into solving them and his life is running from one fire to another. Into this desperate situation comes salvation in the form of the P-CSO 12 step program. The 12 steps are divided into 4 broad categories. They are as copied from the site:
Section 1 – Plan to be Pragmatic | |
![]() |
Step 1: Assess the Value of Your Business SystemsYou |
![]() |
Step
|
![]() |
Step
|
Section | |
![]() |
Step 4: Build Your Security Business PlanEvery business needs a plan, and yours is no exception. In Step 4, you |
![]() |
Step 5: Sell the StoryYou need money to secure anything, in Step 5 you package your business |
![]() |
Step 6: Procure the SolutionA structured procurement process is critical to getting the right |
Section 3 – Run Your Security Organization | |
![]() |
Step 7: Operate/MonitorNow that parts of the solution are implemented, you need to make sure |
![]() |
Step 8: Contain the ProblemInevitably you will have a compromise or breach situation. Dealing with |
![]() |
Step 9: Train the UsersUsers are the weakest link in the security chain, so all the technology |
![]() |
Step 10: Assure Your DefensesIt doesn’t matter if you say something is secure, you need |
Section 4 – Communicate your Value | |
![]() |
Step 11: Benchmark Your ProgressQuantitative measurements prove your worth and ensure your program is |
![]() |
Step 12: Comply without Going NutsCompliance with a variety of both internal policies and legislative |
Following the level headed, plain talking advice will give the reader and pragmatic practitioner a new sense of power over his security domain and a path to success. It does not promise a magic bullet, just a realistic method and approach of dealing with the every day tasks and goals that all security folks live with. The writing style of the book is light and refreshing. It is from Mike the recovering and now pragmatic CSO's point of view. It will feel more like you are reading a short story than another how to business book. I think the Pragmatic CSO will go down as a milestone in the security management arena. I can already envision the follow ons as the pragmatic methodology is more fully fleshed out. I am already thinking of how StillSecure can better align our products to help all of the new pragmatists that will be managing security out there. Congratulations to Mike on a job well done! I am looking forward to what is to come and seeing how the security pragmatists change the security world.















Comments