Picture of a hand turning the lock on a safe
It can be very difficult for IT professionals to crack the code of determining which skills will be essential to the future of IT security

The right combination

In the third part of our definitive guide, we look at how security professionals need to combine technical and communication skills

Written by James Mortleman

As terrorism becomes accepted as a common risk, the defence industry and commercial businesses have demand for IT security skills

Chi Nguyen senior lecturer, University of Portsmouth

The once arcane world of security is changing fast, as businesses seek systems that can meet the challenges of operating in an increasingly connected and collaborative landscape where old organisational boundaries no longer apply.

Security professionals are having to become more adept, not only at understanding the needs of their users and the diverse range of tools, services and techniques available, but also at explaining security options and risks in a language the business can understand.

Christine Ashton, group strategy director at Transport for London (TfL), believes security is changing. “Not long ago, it was mainly about firewalls, anti-virus and low-level stuff. Now the business wants to know things such as how long they should be keeping their emails, whether it is safe for employees to leave BlackBerrys unattended, and so on,” she says.

Ashton is looking for security people to up their game. She does not want professionals who are experts in a particular area, she needs staff who are familiar with policy and how to communicate requirements to senior managers.

“What options do we have? What is the minimum we need to do? Answering those questions requires a different set of skills. It is the difference between being an average guitar player and Eric Clapton,” says Ashton.

“It is not good enough any more to throw a standard on the table and tell the business we have to implement it. Managers need people to interpret these policies in context and present them with options. That requires skills such as consultancy, relationship management and analysis. There is also a need for good project management, because security is often about wide-ranging programmes that encompass a host of things.”

Many IT leaders share Ashton’s sentiments, according to Paul Simmonds, chief information security officer (CISO) of ICI and a board member of user group the Jericho Forum.

“Obviously, you still need point skills, but the real skills will be around translating the business requirements into a security architecture that meets business needs, rather than saying, ‘put a firewall around it’. Managers want to know what is going to give them the best bang for their buck, what options they have and what the risks are of each,” he says.

“Effectively, security professionals need to become internal salesmen for the security function. There is a huge need for those selling skills because you cannot use any technical terms with most users. Security professionals will need to have the ability to develop appropriate analogies, demonstrations or
other techniques to explain a very complex subject area.”

Simmonds says that only the top-flight chief security officers have appropriate selling skills at the moment, but there is a need for such specialisms to permeate lower levels.

Problems are not just confined to business skills. Another issue is that in the wake of the terrorist threat of recent years, many organisations implemented fairly draconian security procedures that some now find overly restrictive. If policies are too difficult for users to follow, they are more likely to subvert them.

“We need to return to some of the usability issues that were put aside for a while after 9/11 and 7/7,” says TfL’s Ashton. “On one level, that is about being more customer-centric, standing in the user’s shoes and asking what they are trying to do and how you can help them. And that applies to both internal business users and external customers ­ – in our case, the travelling public.”

Next week, ICI’s Simmonds will be speaking at the Infosecurity Europe conference in London (22-24 April) on the security issues surrounding social networking.

He believes the trends towards remote and collaborative working are key drivers of organisations’ changing security skills requirements.

“I think there are several related issues hitting IT departments,” he says. “The first is deperimiterisation ­ – the fact that your borders are, in effect, breaking down. Related to that is the shift to collaboration-oriented architectures. The business is asking us ­ – or forcing us ­ – to enable collaboration.

“And if you are going to do business in that environment, it brings a whole new range of security challenges. The problem at the moment is that no one is providing the skills. And there are a number of
skills that will be needed. One is a change of mindset.”

Simmonds says the days of thinking you can just put a firewall around something are long gone. Most firms, he says, are drilling through your firewalls with a rich set of applications ­ – and IT leaders first need to understand the wide range of alternative tools.

“One of the Jericho Forum’s ‘11 commandments’ is ‘understand the context you are developing for’,” says Simmonds.

“If an application works securely in one environment, that does not mean I can use it in a different context and still expect it to be secure. Too often people assume one size fits all, but that is simply not the case.”

TfL’s Ashton agrees that collaborative working has significant security skills implications. “The more we go into shared environments, managing who is on the system, what they are allowed to access and knowing what they are doing becomes ever more critical,” she says. “As a public organisation, we have to share information with all sorts of different bodies, so we need security process skills and the ability to understand the security implications of collaboration and social networking.”

Another area security professionals will need to understand is legal and regulatory compliance, whether industry-specific regulation such as Sarbanes-Oxley for financial firms operating in the US, or government regulation such as the Data Protection Act.

Chris Coulter, a partner at specialist technology law firm Morrison & Foerster, says the Information Commissioner is increasingly pointing to specific technical measures businesses should have in place.

“IT departments will need to be able to monitor the Commissioner’s pronouncements and implement adequate technological solutions to meet these requirements,” he says.

reader comments

related articles

Picture of a tin of paint on a production line

Security made simple

In the second of our four-part weekly guide to security, Lisa Kelly talks to IT leaders taking a best practice approach to security 10 Apr 2008

 

Safe from harm

In the first of our four-part weekly guide to security, we looks at the precautions companies should take 03 Apr 2008

Case study: Ricoh Europe

For Ricoh Europe, responsibility for security sits between business and IT 17 Apr 2008

Infosec: Jericho Forum publishes security model

New architecture promises safer inter-company commerce 23 Apr 2008

ICI signs AT&T for security

Deal includes web-filtering, virus-scanning and spyware-screening 17 Dec 2007

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

Taking a Baracking

I’ve been away for a while driving around the US. I stayed in a different hotel every night for two weeks and... 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

Betfair blimpAnalysis

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

Michael DellAnalysis

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Primary Navigation