Showing posts with label strategy. Show all posts
Showing posts with label strategy. Show all posts

Saturday, August 26, 2017

It's 2017 - why are we still spreading FUD about data security in the cloud?

I was looking into document management options to build upon Google Drive earlier this week. A quick search of document management with google drive yielded, among other results, a post called Google Drive is No Substitute for Document Management. Reading this took me back to conversations years ago about how you can't trust the cloud for your sensitive information and how having your own servers is more secure for your data.

(The post was written in February 2016, so I understand if the post doesn't account for service advancements since then. However, leaving this as is, especially given its high page rank, isn't doing readers a service.)

There are certainly reasons to not rely on Google Drive (or Dropbox, Box, or other cloud file sharing options) for workflow-driven, automation-aided document management, which is discussed in the post. But the first two reasons are just plain inaccurate, and taken at face value, can inhibit organizations who have complex needs and limited resources from taking advantage of commonly used cloud offerings.

Let's start with reason #1 ("Google Drive is Difficult to Administrate"). The basic premise here is that IT administrators don't have the control over folder and file access that they do in more centrally controlled systems, and that control is exceedingly important to maintaining data security. While that sounds bad, let's consider that once someone has access to download a file or folder, they can then share it with whomever they want via email, some other file sharing mechanism, or by printing it out. Further, people are more likely than ever to find the best tools for their work, especially if IT is clinging to admin-centric rather than user-centric services. Data protection and security, absent an environment that is so restrictive that it allows only the most basic functionality at all, is often a combination of technical capabilities, corporate policies, and user training to provide a secure and productive environment.

The roles of policy and training in protecting an organization's data cannot be emphasized highly enough (but here's a few links for your reading pleasure):
Seeing a viewpoint represented by a statement like the one below not only frustrates me, but also indicates policy and training aren't being considered:
For example, your HR employees need to store sensitive information like social security numbers, names, birthdates, and direct deposit banking information. If they store this information in Google Drive, there is a good chance that other employees can see it, too. Obviously, that’s not a good idea.
Storing this data in a spreadsheet in any location is ill-advised and no technology is going to fully protect against it happening. In a security-aware culture, though, the data steward would more likely consult with IT on the best way to store that data and prevent inappropriate disclosures.

On to reason #2 ("Google Drive Only Uses SSL Encryption"). When considering your data security, it's certainly crucial to consider data at rest as well as data in motion. This post asserts that data stored in Google Drive are encrypted in motion, but not at rest, linking to an article that says the same thing. That would be disconcerting and likely put people off using G-Suite. However, Google is fairly upfront about their encryption, making a topic-specific whitepaper available for public view. It articulates how data are encrypted at rest and in motion, as well as how encryption keys are managed. The short version is that with the possible exception of video files, data uploaded to or created in Google Drive/Docs/Slides/Sheets are encrypted. It's also one part of Google's overall security approach. Dropbox and Box have similar information available about their security and encryption approaches.

When considering cloud storage for your organization, security and risk management should be right alongside usability and collaboration in your priority list, and doing your research is important to making a sound decision. The major cloud service providers get it, and have embraced data security and protection as cornerstones of their storage services. Saying otherwise is outdated and unhelpful.

Monday, June 20, 2016

The CEO-CIO Connect

My social media feed recently included an article from Maven Wave Partners' Fusion Blog titled, "CIO vs. CEO: Finding Middle Ground." (note: I used to work at Maven Wave several years ago.) As it was my former employer and I'm a new CIO, I had to read it. And it was thought-provoking indeed -- I didn't necessarily agree with many of the premises, the primary conclusion was spot-on:

"When the CEO and CIO can find middle ground and work together as true partners, the enterprise will achieve true competitive advantage..."

Within the article, the points that stood out to me were (1) the disconnect between the CEO and CIO, and (2) the CIO as a business commodity. Each deserves further consideration, especially at at time where fewer people want to be a CIO.

The disconnect between the CEO and CIO

The article states, "Clearly, the CIO and CEO have roles with notably contrasting job responsibilities... The CEO often understands the core business and customer demands better than the CIO." I'm not going to disagree with these on principle, and it's easy to see this as the world as is. At the same time, we in IT leadership have been told again and again that we must, MUST understand the business in which we operate in order to be a strategic partner and not a business commodity. Virtually every CIO success story I've read can be summarized as follows:
  1. CIO meets CxO
  2. CIO and CxO form partnership around common cause
  3. CIO and CxO make big initiative happen, increasing visibility for both
One of the reasons I was attracted to my current position is the shared idea that the CIO and CEO in fact have roles with notably comparable job responsibilities. Yes, we do different things for the organization (and I'm still figuring out mine). But we share the broad responsibility of both taking the "across the organization" strategic view and enabling ongoing operations. This dual responsibility distinguishes the CIO from a director of IT, who focuses more on operational excellence and continuous improvement within the technology function.

CEOs and CIOs both have the responsibility and opportunity to span the organization.
CIO as a business commodity

So what about the CIO being a business commodity? This is certainly one way to be perceived, especially if the CIO presents as tactical rather than strategic. It's tempting to create an IT strategy, but that helps separate technology from the business. IT strategy also tends to focus on things IT thinks is important, which rarely match what the CEO is trying to do and gives the impression IT isn't part of the team. 

Instead, the CIO's goal should be to ensure technology is part of each facet of the corporate strategy. Ideally, meeting this goal involves the CIO having candid, business-focused conversations with the CEO and being at the strategic table, and doesn't involve the intricacies of platform as a service or network segmentation. However, the world is far from ideal, and the CIO may have to work hard and long to get to that point, possibly exerting influence less directly to get to the table.

This all sounds great in theory.

Doesn't it? That doesn't mean it's an impossibility in practice. Where a CIO begins has everything to do with context -- not every CEO is ready to integrate technology into their everyday thinking. But they don't have to, at least not in detail. If the CEO is willing to consider technology in terms of the same goals as everything else -- help the top line, help the bottom line, and mitigate risks -- then perhaps the conversation can get underway.