Everyone loves toys, and IT/IS administrators are no different. However, it’s a very different thing to buy a new PlayStation for yourself, than it is to spend a considerable amount of your company’s money chasing after yet another buzz-phrase or a vendor-induced panic.

Worse than this is to mis-interpret a regulatory compliance standard (like PCI) and spend all your IT budget on technology, when the vast majority of these standards revolve around policy, procedure and standards. Like security should. Behind every security control, in every regulatory standard, is an intent, and until you have examined what that intent entails for your business, you simply have no justification buying anything.

Both IT and IT Security departments have only one purpose; to enable the business’s goals. That’s it. However, it the business’s responsibility to make those goals VERY clear, and fully support IT/IS when required. This does not happen without robust Risk Management process(es) maintained by a Governance Committee of some sort.

In every organisation for whom I have provided security guidance, they had the exact same dynamic; IT/IS massively overestimated their budgetary needs knowing full well the business side will reduce it as much as possible. Usually to point of making a lot of departments ineffective in any way that matters. Then things like PCI come along and suddenly IT/IS departments have ammunition to up their budgets to meet a supposed business requirement.

The smartest managers used this money to do things properly knowing that PCI compliance will fall out the back end of a security program done well. The majority however line up behind the security vendors like sheep buying exactly what PCI says. Every vendor of firewalls, anti-virus, DLP, FIM, IDS and all the other acronyms have made fortunes while the actual security posture in most organisations has barely improved, if at all.

Any consultant worth his/her salt has stopped a client from buying technology until they are satisfied that the client has the necessary processes in place to determine the ACTUAL need, perform a gap analysis, and exhausted all other options. That consultant also had in mind that buying ANY technology comes with a whole series of post-purchase events that must be complete in order to obtain any benefit from that purchase;

  1. Can existing staff actually USE the technology, or does some / all aspects of it’s running require outsourcing?;
  2. Does the product integrate seamlessly with the existing infrastructure management systems?;
  3. Is the increased security posture in-line with its on-going cost of ownership (management metrics)?;
  4. Has any thought been given to the products life cycle and future-proofing?;
  5. Does the product scale with the business?

…and so on.

The ages old (but still completely relevant) concept of Confidentiality, Integrity, and Availability (C.I.A.) ensures that every security program follows the law of negative returns; the more you have of one, the less you have of the others. This is equally true of the complexity of your program; the more complex your program, the less secure you are.

Technology has its place, no arguing that, but only technology in a business context is sustainable.

[If you liked this article, please share! Want more like it, subscribe!]