A CISO’s Guide to Security Outsourcing

July 13, 2009 by ADMIN · 3 Comments

Daniel Wallace, CISSP, PMP, Information Security Consultant at Grow Forward

While the responsibility for information security’s daily care and feeding can be outsourced, the accountability for compliance, information protection, and assurance will still reside within the organization usually in the CISO’s office.

Is the CISO-as-a-Consultant Model Obsolete?

July 6, 2009 by ADMIN · Leave a Comment

Daniel Wallace, CISSP, PMP, Information Security Consultant at Grow Forward

Compounding the problem for the consultant CISO in the shorter term is that budgets are under downward pressure while the risk of fraud, insider theft and 3rd party exposure is going up. Longer term the financial crisis has forced firms to re-focus on systemic risk resulting in a revival of top-down Enterprise Risk Management efforts.

Making PCI Stand For Coordination & Impact

June 29, 2009 by ADMIN · 1 Comment

Daniel Wallace, Information Security Consultant

It will be no small task in terms of cost and effort for many of the impacted companies to make the transition from self-assessment to onsite 3rd party assessment. However, there are ways to lessen the burden and actually drive business-value from the engagement.