Saturday, February 20, 2016

Tech musing #2 - Project Management as a Security Touch-Point

Article: Project Management as a Security Touch-Point

Link: https://www.cisohandbook.com/Publications/Project-Management-And-Security

Besides commonly emphasized benefits of project management such as the ability to providing a structured way of implementation, project management also benefits security. CISO points out that project management will often create a touch-point with security issues. It comes down to the analysis conducted as part of a project management effort often leading to the discovery of security vulnerabilities prior to this issue becoming a security risk. It is also not uncommon that vulnerabilities in a test system are revealed before going live as result of diligent testing as part of project management.

Additional benefits associated with project management is the framework it provides with clearly defined responsibilities. It will help an organization to allocate specific responsibilities to a specific person or group within the organization. This will reduce the response time to a security incident greatly. Project management also promotes interaction between members of the organization. This ultimately leads to better understanding of each other’s work and promotes cooperation in an effort to mitigate security vulnerabilities.

This article made me realize that project management is not only beneficial for creating a particular system or software. Project management can increase productivity by bringing people together as this article states and might help bringing to light issues with the system or software worked on. Cyber security has become a major issue within the last decades with potential security treats increasing in both numbers and costs. I found it very interesting to discover a link between project management and security risk; something noteworthy for sure.

3 comments:

  1. I have sneaking suspicion you like to read about project management and security. What made this article a good one, though, was it's emphasis on "touch-points." You mention that, but more detail about this seems warranted. I also like the quote that, "The best time to reduce risk in an organization is before the risk is manifested." Seems obvious, but it is often discovered after the risk is manifested. Anyway good article, but you already have PM credit. :)

    ReplyDelete
  2. Hi Dr. Weisband,

    Thanks for pointing that out. Indeed interesting to read on how several parts under the project management umbrella will provoke systems to be evaluated. What I like about this article in particular is how it points out that this evaluation will also lead to increased security. It proves that project management has more benefits than just getting a project done.

    ReplyDelete
  3. Agreed. Increased security is a great mantra for project management.

    ReplyDelete