Government Technology
Government Technology: State & Local Government News Articles

Overcoming Security Funding Roadblocks

Computer Security

Aug 14, 2008, By Mark Rutledge

This article is an excerpt from an upcoming feature, the full version of which will appear this fall in Public CIO magazine  and Web site.

While a security breach is a frightening threat for public CIOs, governments constantly lack enough funding for IT security. Security is one of the least understood management functions, and therefore never receives enough funding to fully protect an organization's critical information. Outlined below are a few key actions CIOs must take to ensure IT security gets the budget it deserves:

  • Increase Appreciation of Security's Significance -- Many executives are wary of shelling out big dollars for IT security. Some believe media coverage of cyber-security stories are exaggerated, with skepticism increasing since Y2K. Others believe industry is trying to scare officials in order to increase product sales. In reality, cyber-security incidents are on the rise, and CIOs must be made aware of the importance of security management.
  • Quantify the Real Cost of a Security Breach -- One way to increase an IT security budget is to show executives how taking precautionary security measures can actually save an organization money. Proactive security activities are usually much less expensive than reactive measures -- with the latter, costs include notifying people of the breach, and supplying free services to those exposed to identity threats. There are other, more qualitative costs that must be included with reactive measures --- with a security breach, there is a loss of trust that may require costly changes in the long run, including the implementation of new and expensive programs.
  • IT Management Must Appreciate the Importance of Security -- IT management often views security as an obstacle that drains their budget and takes up valuable time. However, IT personnel should understand that, with property security, they can actually reduce the time they spend focusing on risk management. Enterprise security systems can automate processes and regulate daily network activity, saving employees time and labor. With proactive security activities, IT management will also avoid the hassle of cleaning up after a security breach.
  • Make All Employees Aware of Security -- Many organizations suffer from a poor understanding of security among all personnel, greatly contributing to the human-error factor in security breaches. CIOs must make sure all employees are security-minded, through IT security training for new employees and education on how their computer use can affect the security of the entire organization.
  • Understand the Best Practices for Technology Adoption -- Adopting security measures is only the first step to staying protected; CIOs and employees must understand how to implement security solutions, and at what scale, in order to protect all of a government's critical information. While following the security mandates required by the federal Office of Management and Budget is a start, this is only the bare minimum for many agencies. Each organization has unique information to protect, and must understand what security measures will best secure their individual agency.

The Bottom Line:
Proactive cyber security can ultimately save agencies money, labor, and time. However, these facts are not yet understood by everyone in the public sector. CIOs must improve upon appreciation, awareness, and adoption in order to make any headway during budget negotiations. Public sector organizations must change how they think about security in order to keep data secure and protect citizens.

Mark Rutledge is the former CIO of Kentucky.



If You Liked This Article, You May Also Like...

Related Products and Services


Latest Government Technology News


Industry Solutions for Government

Read real world deployments of technology in government from our sponsors.

View All Industry Solutions

Marketplace


This section
brought to you by:
Ca - Transforming IT Management

Identity and Access Management Survey
Take the survey to:
  • Win 1 of 10 $25 Amazon Gift Cards!
  • Download the Center for Digital Government's: I Am Who I Say I Am whitepaper

SF Health Plan

  Yes! I would like more information about CA's solutions for Government.

Security Management

The Evolution of Identity and Access Management IAM has become a key tool in the organization’s security and risk management efforts. Many Govt. organizations however, are not realizing the potential of a fully evolved IAM solution. This paper helps them achieve that goal.

How can a comprehensive IAM solution help me reduce security risk and achieve easier compliance? Identity and Access Management (IAM) solutions help you manage users and their access to your IT resources while acheving more effective compliance.

IT Governance

IT Governance: Making the Difference in Cities, Counties and States Project and portfolio management helps government respond to old and new challenges. Featuring case studies from California Department of Agriculture, New York City, and Oakland County, Michigan.

CA Information Governance Solution Brief The CA Information Governance solution helps you solve an array of challenges with unique offerings including federated records management, email management, retention management and business process automation.

Enterprise Management

IT Network Management: State and Local Governments Face New Challenges Network and voice management tools help agancies get optimum performance from today's increasingly complex networks.

Success Stories: San Francisco Health Plan San Francisco Health Plan helps more people access affordable healthcare by simplifying IT management

Success Stories: Social Services Agency, County of Santa Clara County of Santa Clara improves the quality of social services with simplified IT management

CA Network & Voice Management Solution Brief Integrated, fault and performance management for end-to-end service assurance of multi-vendor, multi-technology converged networks.

Risk Compliance and Best Practices

Key Trends in the IAM Market and how CA's R12 Suite Addresses these Trends Identity and Access Management (IAM) has been a major force in the enterprise IT marketplace for years now.This paper will address the question: What's driving interest in IAM solutions?

Network and VoiceManagement for Evolving Business IT management specialist CA provides a foundation for delivering the value of unified network and voice management

A Vision for Dynamic Business Service Management By applying new levels of consolidation, automation and insight, dynamic Business Svc Mgt delivers improved service levels and cost controls

Deploying the CMDB for Change & Configuration Management The Configuration Management Database (CMDB) plays a critical role within the ITIL framework.

The Changing Face of Network Management Automated NCCM tools reduce the downtime and degradation caused by configuration changes.