« The hard part of a key management standard | Main | Should you rotate keys? »

Monday, 29 September 2008

A new report from ENISA

The European Network and Information Security Agency (ENISA) released the report Obtaining Support and Funding from Senior Management while Planning an Awareness Initiative last week. This report provides a framework for information security groups to follow that's supposed to help them maximize their chances of getting important security projects funded. The processes described by this report seems very similar to the one that consulting companies have been advising their clients to use for quite a while.

When I worked for a Big 4 consulting company about 10 years ago, we were advising our clients to use a strategy almost identical to the one that this report describes. Back then, the fact that information security is as much a business issue as a technical issue wasn't very widely understood. Once security groups accept this and learn to speak the same language that other business units do, getting support for security projects is always much easier. Just like the Big 4 were talking about how to do this ten years ago, the ENISA report tells you how to do this today. It's good to see that this is become more widely known.

If you're having trouble getting important security projects funded, this report may be able to give you some useful advice. It's certainly cheaper than hiring a Big 4 consultant.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00e55375ef1c8833010534d47615970b

Listed below are links to weblogs that reference A new report from ENISA :

Comments

Post a comment

If you have a TypeKey or TypePad account, please Sign In.

Voltage Data Breach Index

  • Grab the Voltage Data Breach Index

September 2010

Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30