PUBLISHER: IDC | PRODUCT CODE: 2092446
PUBLISHER: IDC | PRODUCT CODE: 2092446
This IDC Perspective provides a framework by which organizations can assess their security initiatives against three pillars: risk, responsibility, and prioritization. What causes IT security efforts to struggle? While organizations can point to the wrong technology choice or deployment issues, many efforts falter even when the technology used is sound. These initiatives suffer from more insidious issues around alignment, and the effects can be more destructive and harder to diagnose without dedicated effort. A failure to align a given effort and establish consensus on risk, responsibility, and priority among all involved parties can impede or kill security efforts long before any solutions are deployed.Alignment issues manifest in three key areas. Some failures begin with misaligned efforts that focus on the wrong risk, fail to account for the full scope of the problem, or misjudge the business' risk tolerance. Similarly, poor accounting of the authority and responsibility of the people involved can lead to failures to engage the right parties and effect change. Finally, prioritization errors can miss the mark entirely.Solid technical execution won't make up for these insidious issues. What's worse, these challenges are pervasive: They can manifest strategically, but they are also present in everyday interaction and smaller efforts. Despite the importance of alignment, many IT organizations fail to take a structured approach to assessing the health of these factors. In this report, we identify pillars of successful security alignment, illustrate what can go wrong when they are not consistently in place, and present a simple, tactical assessment framework to identify and correct gaps in security efforts."Most security efforts present challenges due to misalignment, and the nature of security work makes these issues more the rule than the exception," said Joel Sandin, adjunct research advisor for IDC's IT Executive Programs (IEP). "Building consensus and clarity around the risk being addressed, accounting for key operational responsibilities and approvals needed, and thoughtful prioritization around risk reduction can avoid costly pitfalls and put security efforts of any scale on a path to success."