IT Security is, at its core, just another kind of risk management. The principles are straightforward to explain – identify the risks, their probability and impact, then work out suitable mitigation strategies to reduce one or the other.
So, how hard can it be to 'deliver' IT security - that is, to make an organisation's IT environment secure? Very hard, is the answer, when we consider just how far technology has come since such principles were first documented. The main challenge can be to identify the risks in the first place, against a background of constant evolution and sudden change.
And it's not going to get any easier given that threats come from an increasing variety of places. Let's summarise - mobile devices and networks; cloud-based applications, services and infrastructure; social networks and online collaboration tools; email and documents; virtualised...