[Dataloss] CEOs deserve jail for data breaches

grexpectations at comcast.net grexpectations at comcast.net
Wed Apr 9 15:27:34 UTC 2008


I don't think the burden should be on the CEOs, unless the security function reports directly.  For many of us, the security function reports into the CIO.  We are challenged with constrained budgets and often the security function competes for funding with business driven initiatives.  In these situations, the CIO is a principle stakeholder in deciding if information protection recommendations are implemented or not.  I've personally witnessed many a circumstance where these types of decisions are filtered from reaching executives higher up in the organization.  My .02.

Regards

-------------- Original message -------------- 
From: "Ghercoias, Catalin" <CGhercoias at TWEC.COM> 

> 
> I agree with the idea. After all these breaches maybe not necessarily the 
> CXX-level executives (maybe the CFO) should be marched to jail but the 
> Directors of the IT who have been told by their Managers of Infrastructure 
> or Managers of Store Services that there is a potential for a breach and 
> "this is what needs to be done/purchased..." but the Director of IT either 
> ignored them or said "this is not critical, it can wait". 
> 
> How many of you Security Engineers, System Administrators, Network 
> Administrators, etc. have discovered big problems (or potential big) in your 
> networks and you notified your Director of IT only to be given one of the 
> answers "this is not critical, we do not have budget for this, it can wait 
> until next year,... or you_fill_in_the_answer_here" or the worse answer I've 
> heard -- "this is a risk that the business is willing to assume" ?? 
> Especially when you told them that egress traffic should be blocked at the 
> firewall level for ... all stores, let's say. 
> 
> -- C. 
> 
> 
> 
> > From: Rich Kulawiec 
> > Date: Wed, 9 Apr 2008 08:52:00 -0400 
> > To: 
> > Subject: Re: [Dataloss] CEOs deserve jail for data breaches 
> > 
> > 
> > This is an excellent idea. As I wrote the other on another mailing 
> > list, the single best thing that could happen for security would 
> > be live video of every Cxx-level executive at TJX being marched 
> > into Leavenworth -- AFTER being stripped of all personal assets. 
> > 
> > ---Rsk 
> > _______________________________________________ 
> > Dataloss Mailing List (dataloss at attrition.org) 
> > http://attrition.org/dataloss 
> > 
> > Tenable Network Security offers data leakage and compliance monitoring 
> > solutions for large and small networks. Scan your network and monitor your 
> > traffic to find the data needing protection before it leaks out! 
> > http://www.tenablesecurity.com/products/compliance.shtml 
> 
> _______________________________________________ 
> Dataloss Mailing List (dataloss at attrition.org) 
> http://attrition.org/dataloss 
> 
> Tenable Network Security offers data leakage and compliance monitoring 
> solutions for large and small networks. Scan your network and monitor your 
> traffic to find the data needing protection before it leaks out! 
> http://www.tenablesecurity.com/products/compliance.shtml 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://attrition.org/pipermail/dataloss/attachments/20080409/4af14879/attachment.html 


More information about the Dataloss mailing list