INTRODUCTION

When I started my career in information security many years ago the thing that struck me most was the lack of engagement with people who weren’t of the information security profession. IT in other departments would shy away from speaking to me as they feared security would stick its nose in and either stop their work or make things more difficult. The business viewed it as a dark art and as long as their security guy said it was okay then that was fine. Most people regarded security as a blocker rather than an enabler. I resolved to change that; I wanted people to see security as an enabler: something that can help you do more business and to create more services. An analogy I like to use when describing security is that of a car: ...

Get Information Security A Practical Guide: Bridging the Gap between IT and Management now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.