The Cloud: How CISOs can embrace it (wisely), not fear it
Cloud computing is one of the great transformational shifts in corporate information technology
Report
It allows businesses to manage their IT needs in innumerable new ways—some of
them great, some of them terrible.
That last part is what worries chief information security
officers.
Part of your role must be to develop a security plan that includes the cloud; rather than one that ignores it. If you don’t, you will be in the position of responding to employees pushing for security reviews during the procurement process—or worse, during deployment. You want to be showing them the way forward.
Report Snapshot
To embrace the cloud fully and wisely, then, a CISO needs to master two roles. First, he or she must participate as part of the team that evaluates cloud providers—bringing the proper security expertise to the finance and business executives eager to use the cloud. Second, the CISO must also know how to evaluate the security of cloud services.
Let’s take each point in turn.