Print This Article Post Comment Add To Favorites Email to Friends Ezine Ready

Don't Take Security Off Your Priority List

By: Wolfgang Jaegel Home |


With the advances of technology and the media hype surrounding security risks, one would assume that security would always remain at the top of Organizations' priority lists.

Security assessments are conducted for our clients to provide them with a snapshot of their security postures, assessing their overall information security programme and corporate governance.

The trends identified security specialists include the following:

Technology is not enough
Organizations' views on security are still primarily focused on hardware and software instead of implementing defence-in-depth strategies. IT departments authorise reactive short-term fixes without looking at the full context of any incidents, or they rely heavily on technology in lieu of programmes that include components of risk management, process, organisation and people.

Organizations rely heavily on security perimeter technologies such as perimeter firewalls and VPNs, with much less focus on internal security. Perimeter technologies need to be expanded and the focus needs to be on internal security measures, such as Internal Segmentation, Intrusion Prevention, Vulnerability Management and Admission Control.

Organizations are realising that in today's business environment, "an internal network is not much safer than an external network". Enterprises are required to provide more users with access to their network and information resources; they have to manage multiple levels of access to their information resources, based on the users' roles and responsibilities, whether it is for customers or business partners requiring access to information, or for mobile users requiring access to applications from outside the enterprise's walls, to name but a few.

People and Organizations can have a big impact
Few Organizations have incorporated internal security training and awareness programmes into their overall security strategy.

Most end-users and business managers have not been made aware of the security risks of accessing the corporate network while working from home or on the move, and how this can impact the organisation.

Organizations can implement as much security technology as they deem necessary, but without making the end-user aware of how their actions can pose a security risk, technology has a limited effect.

Compliance does not equal security
Organizations in general have yet to accept risk management and corporate governance as core to their overall security programmes and there is still a lot of work to be done involving top management.

Traditionally, security has been left in the hands of the IT department. As such, top management is not really involved in the overall risk management plan of the organisation as it relates to IT security.

There is a considerable lack of awareness among business managers regarding how security impacts the organisation. Most business managers also equate compliance with security, to the detriment of the organisation which is often the case.

The Sarbanes-Oxley Act dictates that Organizations need to control access to their systems and also report on the users who have accessed the different systems. To enable this, security tools are required. This doesn't necessarily mean that the organisation is free from hackers, spyware and all other security issues. It just means that the organisation has the ability to check and identify users who access specific systems.

Processes are key
Companies in general demonstrate few efforts around security programme assurance, event logging, incident reporting and pro-active response activities. As such, many Organizations do not have an information security strategy that details processes to further ensure complete security.

Some companies also implement the best security technology available on the market, without having the people or the skills to properly manage these tools, and to ensure that proper processes are followed. A practical example is where users make changes on the network. However, without a change management process in place, this may pose a security risk.

While Organizations often increase spending on security technologies, the number of incidents continue to rise, which shows that a holistic and proactive approach to security is the best way forward.



Article Source: http://www.eArticlesOnline.com

About the Author:
Datacraft is the leading independent IT services and solutions company in Asia Pacific. Datacraft combines an expertise in networking, security, Microsoft solutions, storage and contact centre technologies, with advanced skills in consulting, integration and managed services, to craft IT solutions for businesses.

Tags: , , , , , , ,

Please Rate this Article

 

Not yet Rated

Click the XML Icon Above to Receive Articles Via RSS!

Recent Related Articles From

  • The Specifics Of Project Risk Management
    By: Kelly Bendall | May 14th 2008
    Project Risk Management is an ongoing process. The purpose is to highlight risks and how to reduce/eliminate the impact of the identified risks on the project. Read

  • An Introduction To Enterprise Risk Management
    By: Ned Brumby | Mar 30th 2011
    Risk management is a fundamental principle in any organization, since risk is a reality that needs to be dealt with; irrespective of the business model. There is no straightforward formula for determining how much risk should be allowed by any given organization; for it to get some value or create business opportunities tha ... Read

  • Tips For Selecting The Right Risk Management Software Solution
    By: John Morris | Aug 24th 2006
    Just like a writer requires the right words to create a spectacular story, a risk manager is also in need of the right risk management software to perform his duties admirably... Read

  • Risk Expert Top 5 Security Secrets For Business Personnel
    By: Dr Mark Yates | Sep 30th 2009
    Risk expert top 5 security secrets for business personnel from the risk expert, provides a risk security secrets overview to incorporate into your security plan. Business personnel are often the first to be targeted by professional crime lords & terrorist units worldwide for kidnap and ransom. Learning these risk expert top ... Read

  • Financial Risk Management And Its Application
    By: Daxen Stewart | Mar 4th 2011
    Financial risk is a scenario where the return on a particular investment decision is very less. It could happen that one might partially or absolutely lose the financial benefit of an investment. Some risks could be conveniently faced and fended off but some are absolutely inevitable and head in the direction of a certain l ... Read

  • Difference Between Risk Management And Business Management
    By: JessicaThomson | Oct 14th 2008
    Business management system deals with all the possible phases that are necessary to run a business smoothly. It includes risk management, business outsourcing, product inventory etc. Each of these phases plays a very important part in running the business smoothly. Business management focuses on nearly all of the basic proc ... Read

  • What Is Risk Management And How To Manage Risk
    By: JessicaThomson | Jul 16th 2008
    Risk Management deals with managing these risks affecting the business. It could be better defined as a planned approach for managing uncertainties which is related to a risk. It would include evaluation of risk, developing strategies to manage such a risk and reducing the effects of that risk if that could not be completel ... Read

  • How You Can Make A Successful Risk Management Plan
    By: JessicaThomson | Nov 17th 2008
    Before we start the procedure of risk management planning, we should be clear about how risk management actually works. We should understand that risk is the effect of any event, whether positive or negative. The value of risk could be calculated if we know the probability of any event happening and the impact of that event ... Read

  • Health And Safety In The Workplace To Strengthen Risk Management
    By: JessicaThomson | Aug 29th 2008
    We live in a society which is controversial by instinct. Risk management has become a necessity for businesses, just as important as the maintenance of accounts. The Employees are an integral part of the organization and the health and safety of the employees should be taken care of, if the employer wants to strengthen ris ... Read

  • Consultancy Services In Bid And Programme Management
    By: JessicaThomson | Feb 23rd 2009
    The bid management and risk management training provided by the WPM has helped a large number of organizations to augment their performance. They not only bestow their consultancy services and Prince2 training amid the United Kingdom, but also they offer their services and training in other parts of the sphere, as well. Read


Copyright © 2005-2011 eArticlesOnline, LLC - All Rights Reserved
Terms of Service | Privacy Policy