<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>The Security Catalyst&#187; teamwork</title>
	<atom:link href="http://www.securitycatalyst.com/tag/teamwork/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>harnessing the human side of security</description>
	<lastBuildDate>Wed, 25 Jan 2012 15:57:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>harnessing the human side of security</itunes:summary>
	<itunes:author>The Security Catalyst</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/wp-content/plugins/powerpress/itunes_default.jpg" />
	<itunes:subtitle>harnessing the human side of security</itunes:subtitle>
	<image>
		<title>The Security Catalyst&#187; teamwork</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com</link>
	</image>
		<item>
		<title>The Solution: Leading People, Managing Objects, and Accomplishing Goals</title>
		<link>http://www.securitycatalyst.com/2010/01/the-solution-leading-people-managing-objects-and-accomplishing-goals/</link>
		<comments>http://www.securitycatalyst.com/2010/01/the-solution-leading-people-managing-objects-and-accomplishing-goals/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 11:00:48 +0000</pubDate>
		<dc:creator>Guest Blogger</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[change]]></category>
		<category><![CDATA[leadership]]></category>
		<category><![CDATA[teamwork]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2687</guid>
		<description><![CDATA[by Martin Fisher Those who know me have come to expect me to â€œcorrectâ€ them whenever they say â€œmanage peopleâ€. â€œObjects are managed, people are led,â€ is my usual retort. Sometimes I am met with a blank look, sometimes with a exasperated grimace, and sometimes (and not nearly often enough) by a questioning stare. â€œWhat?â€ [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.securitycatalyst.com/wp-content/uploads/2010/01/leader.jpg"><img class="size-full wp-image-2689 alignright" title="leader" src="http://www.securitycatalyst.com/wp-content/uploads/2010/01/leader.jpg" alt="" width="300" height="224" /></a>by Martin Fisher</strong></p>
<p>Those who know me have come to expect me to â€œcorrectâ€ them whenever they say â€œmanage peopleâ€.</p>
<p>â€œObjects are managed, people are led,â€ is my usual retort. Sometimes I am met with a blank look, sometimes with a exasperated grimace, and sometimes (and not nearly often enough) by a questioning stare.</p>
<p>â€œWhat?â€ the quizzical friend often asks. â€œThere&#8217;s not a difference worth mentioning.â€</p>
<p>Nothing could be further from the truth and nothing, in my opinion, has done more to impede the progress of the information security profession.</p>
<p>The abject failure of leadership, from senior ranks, through middle management, to front-line supervisors has led to a culture that glorifies â€œmeeting expectationsâ€, extols the virtue of â€œaccomplishing goalsâ€, and is satisfied with â€œgetting the job doneâ€. Don&#8217;t get me wrong â€“ these things are important â€“ but they miss the vital difference: That a dynamic leader can take a group of people and almost always â€œexceed expectationsâ€, â€œsurpass goalsâ€, and â€œget the job done betterâ€ and still have a happier team and more satisfied customers.</p>
<p>â€œHow does that happen?â€ asks the still-quizzical friend, â€œIsn&#8217;t meeting expectations what we&#8217;re here for? Isn&#8217;t that enough?â€</p>
<p>Sadly, it isn&#8217;t enough.</p>
<p>All people appreciate leadership. Everyone inherently wants to belong to a team that accomplishes exceptional results. Nobody wants to be in an organization that doesn&#8217;t excel.</p>
<h3><span style="font-family: Arial, sans-serif;">The key to this is the Leader.</span></h3>
<p>Leaders determine, by applying their leadership talents, just how far the team will go. Setting a goal and managing to that goal ensures that any additional capability is forever lost. Managing to a goal guarantees that the exceptional capability that is native to any team will be lost in a desire to just do â€œenoughâ€. When we manage people, instead of lead them, we are condemning ourselves to forever experience sub-optimal results, never knowing what could have been accomplished.</p>
<p>â€œBut my team is happy and my customer is satisfied. Doesn&#8217;t that mean I&#8217;m succeeding?â€ asks the friend as their frustration with the conversations grows. â€œYou&#8217;re making more out of this leadership thing than it really is, aren&#8217;t you?â€</p>
<p>This is the point where the friend has reached an almost Matrix-esque moment&#8230;</p>
<p>â€œTake the blue pill and this conversation ends. Everything goes back to the way it was and you can believe anything you want to believe. But take the red pill, and I&#8217;ll show you how you can take the leadership skills and talents you have and use them to transform yourself and your team. I&#8217;ll teach you how to truly get more done with more satisfaction.â€</p>
<p>Which pill, my friend, will you take?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/01/the-solution-leading-people-managing-objects-and-accomplishing-goals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trust, Sociology, and IT</title>
		<link>http://www.securitycatalyst.com/2009/05/trust-sociology-and-it/</link>
		<comments>http://www.securitycatalyst.com/2009/05/trust-sociology-and-it/#comments</comments>
		<pubDate>Wed, 20 May 2009 11:00:45 +0000</pubDate>
		<dc:creator>Ioana Bazavan Justus</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[relationships]]></category>
		<category><![CDATA[teamwork]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1773</guid>
		<description><![CDATA[by Ioana Justus In my last blog, I talked about how to build trust with a customer, and the advantages of doing so. By building a relationship of trust, communication becomes more open, allowing the customer to feel comfortable sharing their needs, and allowing the IT service provider to better customize service and anticipate needs. [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><img class="alignright size-full wp-image-1774" src="http://www.securitycatalyst.com/wp-content/uploads/2009/04/for-mysite.jpg" alt="Ioana Justus" width="145" height="150" /><strong>by Ioana Justus</strong></p>
<p class="MsoNormal">In my last blog, I talked about how to build trust with a customer, and the advantages of doing so.<span> </span>By building a relationship of trust, communication becomes more open, allowing the customer to feel comfortable sharing their needs, and allowing the IT service provider to better customize service and anticipate needs.<span> </span>This concept also extends to intra-IT interactions â€“ or regular life interactions, for that matter.</p>
<p class="MsoNormal">Sociologists will tell you that humans are social creatures â€“ even the most introverted of our species require interaction with others.<span> </span>There is also the concept of the â€œinner circleâ€ â€“ each person has an â€œinâ€ crowd that they trust and want to interact with.<span> </span>Evolutionarily, having such a group ensured survival: the group would mutually protect each other and they worked together to find food and raise children.<span> </span>The flip side of this evolutionary model is the rest of the world: If youâ€™re not part of the inner circle, youâ€™re not trusted and are thus treated with suspicion, prejudice, or even disdain.<span> </span>Individuals in your inner circle get the benefit of the doubt when they do something wrong, and you are compelled to help them through it.<span> </span>Individuals not in your inner circle are assumed to be malicious when they do something wrong, and you are compelled to be defensive and accusatory toward them for it.</p>
<p class="MsoNormal">It frequently surprises me how people assume that things in the IT or business world work so differently than they do in daily life, when there is actually little or no difference.<span> </span>We are the same humans with the same genetic make-up whether weâ€™re home in our sweats or at work in our suits.<span> </span>Everyone knows that the best way to get a new job is to network with people at the target company, and many a manager has been accused of favoritism â€“ Mary got a perk that I didnâ€™t get because the boss â€œlikes her betterâ€ (i.e., trusts her more) than me.<span> </span>Even security networks are built on trust (e.g., PGP): if I trust you and you trust John, then I can trust John.<span> </span></p>
<p class="MsoNormal">So it stands to reason that if we can increase trust in the workplace, everything gets better: issues get resolved faster, there are fewer nasty surprises, there is greatly increased communication, and a strong desire to be inclusive.<span> </span>This then results in better collaboration between IT teams, which increases sense of ownership that in turn decreases errors and improves the overall quality of deliverables.<span> </span>All of this makes the customer â€“ and thus the boss â€“ happier.</p>
<p class="MsoNormal">But how do you go about this?<span> </span>Theoretically, itâ€™s simple: communicate and include.<span> </span>Practically, itâ€™s quite a bit more challenging.<span> </span>Make it a point to build trust with your coworkers, especially where you know it doesnâ€™t exist today.<span> </span>At work, your inner circle is most likely your immediate team.<span> </span>But you probably work regularly with other teams.<span> </span>Are you accusatory of them?<span> </span>Do you have a less than impressed opinion?<span> </span>Do you think they screw up or are sub-par?<span> </span>Do they point their fingers at you?<span> </span>Those are the individuals you most want to target.<span> </span>Be sure to have face-to-face meetings with them â€“ itâ€™s a lot harder to think someoneâ€™s a jerk when theyâ€™re sitting right there.<span> </span>When you invite them to the table, ask everyone (including you and your team) to leave their prejudice at the door.<span> </span>Talk about whatâ€™s going wrong openly and honestly, with the intent to fix the problem, not lay blame.<span> </span>This may take some time, but have the good will to keep trying, and consider engaging a practiced facilitator if needed (many people are naturally good facilitators, but if you need someone who has been specially trained, try looking in HR or the training department).<span> </span>Extend gestures of goodwill by inviting the other team to an outing (e.g., lunch or drinks after work) or to meetings that they shouldâ€™ve been invited to but werenâ€™t.<span> </span>Above all, really listen to their perspective and make an effort to see their point of view.<span> </span>It might take a while, but what youâ€™ll notice over time is increased respect and much smoother workings between you.</p>
<p class="MsoNormal">It may be a bit pie-in-the-sky, but imagine if you had trust with every team you worked with.<span> </span>I guarantee youâ€™d be a happier employee and youâ€™d enjoy your job a lot more.<span> </span>Youâ€™d also get work done faster with higher-quality results, making your customers and supervisors happier, too.<span> </span>And in this tenuous economic climate of cost-cutting and down-sizing, thatâ€™s maybe as close to job security as any of us can get.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/05/trust-sociology-and-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Three Ways to Avoid â€œWheel Reinventionâ€ &#8211; and Build a Better, Trusted Solution</title>
		<link>http://www.securitycatalyst.com/2008/07/three-ways-to-avoid-%e2%80%9cwheel-reinvention%e2%80%9d-and-build-a-better-trusted-solution/</link>
		<comments>http://www.securitycatalyst.com/2008/07/three-ways-to-avoid-%e2%80%9cwheel-reinvention%e2%80%9d-and-build-a-better-trusted-solution/#comments</comments>
		<pubDate>Mon, 07 Jul 2008 13:15:05 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[teamwork]]></category>
		<category><![CDATA[trustmark]]></category>
		<category><![CDATA[truthiness]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=469</guid>
		<description><![CDATA[The last article in this series explored the top three reasons why group have a tendency to reinvent the wheel (read it here, or the entire series started here). And now, some solutions: Beyond the frustration caused by an approach that simply recreates the wheel, the result is often a solution that is not trusted [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<p class="MsoNormal"><em>The last article in this series explored the top three reasons why group have a tendency to reinvent the wheel (<a href="http://www.securitycatalyst.com/2008/07/why-teams-reinvent-the-wheel/" target="_blank">read it here</a></em><em>, or the entire series started here</em><em>). And now, some solutions:</em></p>
<p class="MsoNormal"><em><span style="font-style: normal;">Beyond the frustration caused by an approach that simply recreates the wheel, the result is often a solution that is not trusted and therefore readily cast aside in favor of the next offering. To put a stop to this cycle requires taking a different approach. Success has to be based to fundamentals and sound principles.</span></em></p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>How to do it? </strong></p>
<p class="MsoNormal">A key part of the solution is to enter into deliberate discourse (note: this is a central theme of <em>I</em><em><a href="http://www.securitycatalyst.com/into-the-breach/" target="_blank">nto The Breach</a></em> and a topic I am passionate about). More voices with an opportunity to review, consider and contribute have the potential to lead to a better product. For this to lead to a better product requires a strong leadership team with enough expertise to guide and the skills to help facilitate and negotiate the final result.</p>
<p class="MsoNormal">Instead of starting with a blank slate, it is a good practice to build on the success of others. When it comes to strategies that protect information, we have plenty of choices â€“ frameworks like ISO 2700x, PCI, FISMA, etc. However, limiting the solution to a narrow set of industry standards may not yield the best results. Sometimes, real progress comes at the intersection of industries (to gain more insight on this approach, consider reading: The Medici Effect) â€“ leveraging how the medical, engineering or other industries have dealt with and handled challenges may bring valuable insight to the effort at hand.</p>
<p class="MsoNormal">The advantage to building on the validated and transparent work of others is the ability to avoid conjecture and â€œgut feeling.â€ <strong>This is the challenge: there are few shortcuts to spending the time to outline, think, plan, distill, check, cross-reference.</strong> This is an area where transparency really provides a benefit.</p>
<p class="MsoNormal">When the group of professionals is assembled, here are three steps to harnessing the collective power, building on the wheel (instead of building a new wheel) and reaching a point of success:</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>1. Capture and distill frameworks (or solutions)</strong></p>
<p class="MsoNormal">Start by presenting a model to work from, based on an existing solution. In general, individuals and groups struggle to create but excel at editing and revising. With this in mind, selecting an initial framework or set of solutions to present to the group acts as a strawman [<a href="http://en.wikipedia.org/wiki/Strawman"><span>http://en.wikipedia.org/wiki/Strawman</span></a>]. This has the added benefit of allowing people to beat on the framework(s) instead of each other.</p>
<p class="MsoNormal">The frameworks or solutions can either be selected in advance or decided by the team. Allowing the team to decide may provide for more diverse results but requires more time and a stronger facilitator (who possesses deep subject matter expertise). Stronger frameworks and solutions are those that have already been publicly validated and are more transparent. This suggests the â€œheavy liftingâ€ has already been done and the team can focus on refining and tailoring what already exists from multiple sources into the solution required.</p>
<p class="MsoNormal">More important that just compiling a list of viable frameworks and solutions is how they are captured and processed. As the elements are suggested, reviewed and documented, look not only for the similarities, but also the distinctions between them. Working to understand why specific elements were either included or excluded may also reveal key insights that aid the development of a stronger solution. Note the intended audience and users of the solution and how it is received. It may be useful to note the level of maturity, too (since that provides some insights).</p>
<p class="MsoNormal">This process generates a lot of discussion â€“ this is good, and leads to the second point.</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>2. Capture and distill the running dialogue</strong></p>
<p class="MsoNormal">More important, perhaps, than the solutions selected in the last step is the running dialogue that occurs as part of the process. Yet few organizations take the time or make the effort to capture that solid gold value.</p>
<p class="MsoNormal">Ultimately, the discussion â€“ the true process of negotiation and coming to a common understanding â€“ is precisely what allows a group to build the final product. While the discussion is natural, here are three important questions to ask, answer and record during this process:</p>
<p class="MsoNormal">a. What works &#8212; and why?</p>
<p class="MsoNormal">b. What does not work &#8212; and why?</p>
<p class="MsoNormal">c. How is this applied &#8212; and why?</p>
<p class="MsoNormal">Look for specifics. This is an area where people tend to rely on &#8220;truthiness&#8221; â€“ which, to a certain extent, may be okay. In the overall discussion, however, guide people back to more concrete grounding by asking more questions to ensure everyone shares a common understanding (which is not necessarily the same as a common opinion!). The next segment will explore the benefit of capturing this conversation and making it available in the future.</p>
<p class="MsoNormal">As the conversation continues, there is one more step to increase the overall value.</p>
<p class="MsoNormal"><strong>3. Capture and distill references</strong></p>
<p class="MsoNormal">The value of having experts together in a room is their collective knowledge â€“ informed by experience, training and a vast array of resources. Therefore, it is incredibly valuable to regularly ask this group to cite the references they find of value.</p>
<p class="MsoNormal">As the discussion rages on (if you have been part of a working group, rage is definitely the right word), asking people to take the time to cite the references that support their assertions returns focus to the fundamentals.</p>
<p class="MsoNormal">Not only does this improve the overall framework, but this also improves how it is applied and verified (as we will explore in the next sections).</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>Bottom Line</strong></p>
<p class="MsoNormal">Bring together a small, tight team that works well together. Welcome as many voices into the process as reasonable. Take the time to distill and overlay what already works.</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>How this Applies to Trustmark</strong></p>
<p class="MsoNormal">When <a href="http://www.comptia.org/businesscred/securitytrustmark.aspx" target="_blank">Trustmark</a> gets this right, it will essentially be an overlay on the entire industry â€“ explaining where, how and why the different control families and control objectives can be met. This is important, since it allows for additional regulations or efforts to be acceptable without prescribing a set way of working. But whether working on Trustmark or a new process to protect information, following these steps leads to a stronger &#8211; and more trustworthy &#8211; result.</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><em>Up Next: the second challenge facing Trustmark and similar efforts is in how the solution is applied. We examine this challenge with potential solutions before moving on to the final challenge of how the solution is measured and verified. </em></p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal">If you enjoyed reading this article, please take a moment to either subscribe to the RSS feed (<a href="http://www.securitycatalyst.com/feed/">www.securitycatalyst.com/feed/</a>) or sign up for <a href="http://www.feedblitz.com/f/f.fbz?AddNewUserDirect" target="_blank">free updates by email</a>. Use the buttons below to print this article or share this with friends and colleagues that will benefit from this.</p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/07/three-ways-to-avoid-%e2%80%9cwheel-reinvention%e2%80%9d-and-build-a-better-trusted-solution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

