Task force: Infosec must be part of corporate governance

Share this article:

A task force of the National Cyber Security Partnership (NCSP) Monday released its recommendations for organizations to incorporate cybersecurity into their corporate governance systems.

"This is not a technology, CIO, or chief security officer issue," Bill Conner, co-chair of the task force and president and CEO of Entrust, said in a media conference call. "The issue is a corporate governance, board level and CEO issue."

The group said infosec governance needs to be voluntary instead of mandated by government. To that end, it urged companies of all sizes to adopt the infosec governance framework it developed and indicate on their web sites their commitment to infosec governance. The task force also developed a "core set of principals" to help organizations develop infosec governance programs.

In addition, the group recommended that the Committee of Sponsoring Organizations of the Treadway Commission (COSO) revise the Internal Controls-Integrated Framework so it clearly addresses infosec.

"We want to make it clear that the leaders of organizations today already have a fiduciary responsiblity to have strong information security," said Art Coviello, task force co-chair and president and CEO of RSA Security.

The recommendations from the NCSP's Corporate Governance Task Force are the latest from the NCSP, which is a coalition of business and technology groups. Other NCSP task forces previously released recommendations on improving software security, security awareness, and developing early warning systems.


Share this article:

Next Article in News

Sign up to our newsletters

More in News

Brazilian president signs internet 'Bill of Rights' into law

Brazilian president signs internet 'Bill of Rights' into ...

President Dilma Rousseff signed the legislation on Wednesday at the NetMundial conference in Sao Paulo.

Android trojan sends premium SMS messages, targets U.S. users for first time

Android trojan sends premium SMS messages, targets U.S. ...

An SMS trojan for Android, known as FakeInst, has been observed sending premium SMS messages to users all over the world, including, for the first time, the United States.

Report: DDoS up in Q4 2013, vulnerability scanners leveraged to exploit sites

Report: DDoS up in Q4 2013, vulnerability scanners ...

Researchers observed 346 DDoS attacks in the final quarter of 2013 and attackers used Vega and Skipfish vulnerability scanners to exploit web flaws at financial companies.