In my actual post I have thought a lot about services "hyperoriented" organizations. I remark "sevices oriented" because it is, most of the time, an empty word.
I have though about how difficult may be try to implement a security project and the needed compromise from business level, etc. and all our, project manageres, claims about the profound gap between us and C-level.
I am thinking about and proposing a different model: being "services oriented". Providing security services is usually done by "external" providers but not usually though possible by "internal" providers. However I think this maybe a very good model for two reasons: interfaz and sales.
Offering security services establishes an "interfaz" between the organization and the security team. Step by step defines what work is responsibility of the CIO and what not. Not in a moment, not easily but possible. Also clarifies for the security team the work they must do.
Thinking about the services offered as "sellable" services the view point change and the sales effort may increase and change way. The metrics for evaluating security include marketing penetration, for example, customer satisfaction, and repetitive buyers.
I want to develop this idea but I want to share it with you and enjoy any subsequent discussion.
2009-09-08
Subscribe to:
Post Comments (Atom)

0 comments:
Post a Comment