Building a Security, Risk & Compliance Program from the Ground Up 
Mike Rothman
Senior Vice President, Strategy
eIQnetworks
Presentation Abstract:
Browse any major newspaper, industry journal or security blog today, and it’s easy to see that the numbers of significant breaches of data – from credit card information to health records – continue to increase at a rapid pace. Simultaneously, the number of regulations, best practices, and internal drivers defining how organizations must improve their information security posture is constantly evolving, while business partners and industry groups continue to ramp-up security and privacy requirements for managing data.
While these factors are driving the need for organizations to adopt effective security and compliance practices, by and large they are woefully short on telling organizations how to create the business processes to make these security and compliance efforts happen. The gap between recognizing the problem and developing a comprehensive – and effective – solution to address it can be daunting; across the entire spectrum of public and private industry, organizations continue to experience difficulty integrating security, risk and compliance management.
In this presentation, we will evaluate one approach that many organizations have used to build an effective security, risk and compliance business process. By integrating the right combination of people, processes and technology, we will demonstrate how organizations can establish a comprehensive program that both holistically addresses security and compliance, and has the flexibility to evolve as the organization’s ever-changing set of risks, threats, and compliance needs change.
Bio:
Mike Rothman comes to eIQnetworks with almost 20 years of industry experience. Starting his career as a programmer and a networking consultant, Mike was a vice president at META Group spearheading the firm’s initial foray into information security research. Mike left META in 1998 to found SHYM Technology, a pioneer in the PKI software market and then took vice president of marketing roles at CipherTrust and TruSecure, providing experience in marketing, business development and channel operations for both product and services companies. In 2006, Mike founded independent research firm Security Incite to help customers wade through the morass of noise and confusion that marks a security professional’s existence.
Through his Pragmatic CSO book and methodology, the Security Incite blog and Daily Incite newsletter, Mike provided an unvarnished opinion of what security professionals needed to worry about and presented a program to help security professionals position security within the context of their business. Mike has a Bachelor of Science Degree in Operations Research and Industrial Engineering from Cornell University..








