Skip to main content

Active Directory Security Needs Immediate Attention

Page 3

CIO VS CISO:

WHY BAD ACTORS ARE OWNING ACTIVE DIRECTORY Every organization suffers from a lack of visibility and responsibility around Active Directory (AD) security. Security teams do not have the depth of knowledge on AD, where IT does not have the time or desire to secure AD fully. Thus, Active Directory is the main target of nearly every cyberattack today.

The CIO The CIO is responsible for ensuring that technology is leveraged and running to support the organization. This means that the technology must be available “at all costs” so employees can perform their jobs and the company remains profitable. The CIO is normally responsible for Active Directory, which is central to authorization and authentication.

The CISO The CISO is responsible for information security. This means that data, devices, services, network, and nearly everything technology-focused is secure. The CISO normally is responsible for the SOC and all of the security analysts. There is a very common issue that exists with regard to technology in nearly every organization. • CIOs want things to run so the company can be profitable, regardless of the overall security. • CISOs want things to be secure, regardless of the overall functionality of the organization. These two conflicting concepts can cause a significant technical and strategic split for the organization.

ACTIVE DIRECTORY SECURITY NEEDS IMMEDIATE ATTENTION

3


Turn static files into dynamic content formats.

Create a flipbook
Active Directory Security Needs Immediate Attention by complytec - Issuu