CISOs: Missing an Opportunity to Partner with Your CDO?

CISOs can tap into the CDOs data knowledge and governance skills, while CDOs can tap into the CISO’s knowledge of internal and external threats.
Recently, I was talking with a major analyst firm about data and security. The name of the firm will not be mentioned to protect the not-so-innocent. During this call, I was amazed to learn that most CISOs remain focused – even with their increasing board level visibility – on protecting their enterprises from outside intrusion or compromise, but not on protecting their enterprise’s most valuable asset – data – from threats internal and external.
I was told most are hyper focused on what the authors of the ‘Privacy Engineers Manifesto’ call the “access stage protection.” The unfortunate truth, says Constellation Research’s Dion Hinchcliffe, “there is no perimeter. You can’t trust much of anything anymore, even inside a perimeter. It seems a bit sad given the huge promise of the Internet to connect everyone. But the problem is it connects everyone.”
Former CIO Wayne Sadin agrees and says, “I particularly dislike ‘perimeter,’ because it implies ‘inside = safe, outside = dangerous.” While access stage protection remains an important component of the security architecture, there is an opportunity for CISOs to do more and at the same time, to partner with their chief data officers to protect the real gold for their organizations, their data.
The reason for taking this step is that the bad guys – as CISOs know – have become more sophisticated. Instead of breaking down the organization’s front door, they have found a proverbial window to enter from. They are doing this by targeting the DBAs who control access to the database and using phishing and other techniques to get their hands-on customer data. This happened to a major healthcare payer, a few years ago, and the hackers got access to everything within the organizations customer database. This creates what I like to call an all or nothing game for enterprise data.
And yes, education remains important, but it is so easy to get fooled as I attested to in a recent article in Datamation Magazine. So, the question is: why aren’t CISOs and CDOs actively protecting their firm’s data?
This is a great opportunity for a partnership because CISOs can tap into the CDOs data knowledge and governance skills, while CDOs can tap into the CISO’s knowledge of internal and external threats.
A core element of getting data protected is getting systematic about data governance. With data governance, no one – regardless of title or level – should have access to all data. What is needed is to establish “principles and processes to build controls and messages into processes, systems, components, and products that enable the authorized, fair, and legitimate processing of personal information” (The Privacy Engineers Manifesto, page 29).
Specifically, the opportunity is to setup data governance for personal identifiable information (PII) and to comply with ISO 27001. The question CISOs and CDOs should be having at this point is what is involved in doing this well especially within legacy organizations.
I want to suggest there are three steps:
Everything needs to start by creating data stewards. And please, data stewards cannot come from the IT organization as much as IT may care about data.
Only the business owners of data understand how data should be governed and the compliance requirements their industry may demand in terms of personal identifiable information (PII). The first task, therefore, is establishing data owners for data classes.
With this in place, data stewards need to ensure that data policies for how data is maintained, managed, governed, and secured for the ultimate data owners. While there are clearly privacy types, here we are focused on security, ethics, and privacy.


