Government Technology
Government Technology: State & Local Government News Articles

Finding Security in an Unsafe World

Bookmark and Share
Comment

Oct 10, 2006, By Alison Lake

The theft of 26 million veteran records in May demonstrated how easily sensitive information can fall into unauthorized hands. Despite growing demand for online services, such incidents may cause citizens' trust to erode, and gradually turn them away from enhanced online government services, according to a July 2006 National Association of State Chief Information Officers (NASCIO) brief.

This brief, Born of Necessity: The CISO Evolution, states that this trend can only be reversed by capable chief information security officers (CISOs) who can align policy with technology -- which is no easy task in state government.


Changing With the Times
In the brief, NASCIO explained that increased concern for both personal protection and homeland security, along with the rising demand for citizen services, make protecting data more important.

The CISO position has evolved in response to these dynamics, the brief said, and become more relevant in today's world.

"We are pleased that states at all levels of maturity regarding their IT security programs will benefit from this brief, which discusses how the state CISO position has evolved from a provider of perimeter defense to IT security strategist, and how that position is likely to evolve in the years to come," said Brenda Decker, co-chair of NASCIO's security and privacy committee and CIO of Nebraska.

NASCIO's 2004-2005 Compendium of Digital Government in the States study, scheduled for release later this year, reported that 29 states had a CISO. What is the urgency about hiring CISOs? It's a jungle out there, according to NASCIO, and the remaining states need to step up.

Born of Necessity cites not just outside hackers, but threats from within state government, including large and multitentacled agencies; introduction of personal technology into office computers via PDAs; instant messaging and MP3 players; outside contractors; and unknowing carelessness of employees. And as citizen demand for more online services increases, the number of new applications and enhancements to existing ones grows, raising the security risk. More users access systems and enter personal information, and IT services grow to accommodate demand.


Leading People and Policy, Not IT
"In light of the current IT threat environment, states need the CISO or equivalent position to strategically address these threats by creating and executing policies on an enterprise level, and to provide guidance to the state CIO and state agencies," the brief states.

States are in different stages of IT security planning, and NASCIO has a blueprint for the CISO job description, with recommendations for training and qualifications, mandates and compensation.

At present, most CISOs report to the state CIO, but the brief recommends a partial separation of powers, and asks, "For a state's IT projects, does the fact that the state CIO has a responsibility to bring those projects in on time and within budget compromise security if the state CISO reports to the CIO?"

In other words, a conflict of interest is possible, and states should build authority and independence into the CISO's position for maximum effectiveness.

Building relationships inside and outside of government is a crucial component of the CISO's job, according to the NASCIO brief, which also states that IT will be most secure when the CISO can both articulate the need for security and work with stakeholders.

Mary Carroll, CIO of Ohio and co-chair of NASCIO's security and privacy committee, agreed. "As the role of the CISO has evolved, the state CISO must now focus on relationship building across the state, and even outside of the state."

NASCIO envisions the CISO as an educator with broad influence in the governor's office, legislature and all state agencies. "With IT as an enabler of so many critical government functions," Carroll said, "the state CISO must be


Latest Government Technology News


Industry Solutions for Government

Read real world deployments of technology in government from our sponsors.

View All Industry Solutions

Related Products and Services

Marketplace


Get Public CIO's Bi-Weekly Newsletter
This section
brought to you by:

CA RC Q1 2010 Resource Center

Take our Identity
Lifecycle Management (ILM) Survey

Can your organization keep pace with its growing demands while enforcing security controls?

Mainframe

White Paper: The Mainframe Opportunity IT Strategies For Achieving Breakthrough Value

Forrester conducted interviews with CIOs/CTOs of mainframe users in the US and Europe to better understand their strategies in the use of the mainframe.

Strategy Paper: CA's Mainframe 2.0 Strategy Roadmap

Fully capitalize on the potential value offered by the mainframe as the availability of mainframe professionals becomes increasingly constrained.

MF 2.0 Product Brochure

Mainframe 2.0 is CA’s new and far-reaching initiative that is changing the way the mainframe is managed forever.


Cybersecurity

IDC White Paper - Identity Lifecycle Management: Bringing Together Security, Identity and Compliance

Read this to learn about the technology and best practices needed to manage your identities throughout their lifecycle.

I Am Who I Say I Am

This paper discusses the drivers, responses and challenges associated with information security in Government.

Simplify and Secure: Managing User Identities Throughout their Lifecycles

Find solutions that simplify, automate and secure the activities for creating and modifying user identities and roles throughout the organization.

Virtualization / Cloud Computing

White Paper: Integrated Infrastructure and Performance Management for Virtualized Environments

Government agencies use virtualized environments to decrease costs, consolidate data centers and reduce environmental impacts.

CA Virtualization Management

CA Virtualization Management solutions provide integrated end-to-end management, automation and security which drive better outcomes.

Working Together to Maximize Business Value of Your IT Investments

VMware and CA have responded to your requirements by forging a solid partnership focused on your enterprise's needs.

Project and Portfolio Management

A Life Cycle Approach to Grants Management

Using project management at every stage of grant administration can maximize funds now and for the future.

A Platform for the New Transparency: Meeting the Challenge of ARRA Grants Management in State and Local Government

The sheer size of ARRA and new grant opportunities has had a tremendous impact on the workload of grants management staff. But the size of the program is only part of the story.

Success Stories: IT Governance: Making the Difference in Cities, Counties and States

Decision-makers need to align IT projects with organizational goals.  See how three agencies achieved this.

Government Jobs

Browse hundreds of public sector career opportunities in GovTech's new jobs section. Popular job searches: government IT, public safety, GIS, transportation, CIO, security, health