According to the 2002 Australian Computer Crime and Security Survey, 70 per cent of Australian organisations increased their expenditure on information security in the 12 months prior to the study being conducted. The survey was produced jointly by AusCERT, Deloitte Touche Tohmatsu and the NSW Police Service, and its findings may well reflect how prominent security has become in the minds of chief executives and boards, especially since September 11, 2001. However, to be effective the right person, at the right level in the organisation, needs to be in charge of information and systems security, and this has not always been the case.
In the late 1980s and early 1990s, a manufacturing company in Australia decreed that information security should be taken out of the hands of the IT department as it was considered to be a case of the fox guarding the chicken coop. If the reasoning behind this was flawed to begin with, the consequences were pitiful. A succession of unqualified and unsuitable"redeployees" ended up being appointed to the new position of corporate security officer, primarily because the company couldn't find anything else for them to do. A power game developed between the heads of business units and IT as to who could access what, how and when; and the end result was cumbersome and ineffectual processes that impeded both IT personnel and end users in doing their jobs.
That may be an extreme example, but while whoever is in charge of IT security need not necessarily sit in the IT arena , most would agree that the incumbent does need some technical grounding, given the complexity of the technology involved. This is very much the view of Stephen Srede, information security manager for AMP Financial Services, whose background is in networking and programming.
"My background is technical, so I understand the way things fit together and I think it is very important to have someone in the team who has a really good technical understanding and knowledge of how things work from the ground up. It does seem to vary a lot, though; some people come from an audit background and some people come from a more mana-gement oriented background," Srede says.
Srede's team of four is responsible for information security across Australia and New Zealand. Principally, this is for AMP Financial Services, he says, but they also work with other companies within the AMP Group. The role is a full-time one for Srede and he believes most large organisations these days do have at least one full-time person dedicated to information security, if not a team as in his case.
According to Srede, he and his team set security policy in conjunction with the business. Other duties include analysing and evaluating what security-related technologies need to be in place, such as firewalls and intrusion detection systems, and where, acting in an oversight capacity, procedures are working correctly and investigating anomalies. He considers viruses still to be the biggest threat to AMP's security."Although the threat of hacking receives more press and is on the increase, and internal threats such as fraud are always a risk, viruses are the most disruptive to the organisation," he says."If a virus comes through and the [appropriate] infrastructure is not in place and up to date, the cost is easily measurable as being very large."
Prior to joining AMP in February 2002, Srede held a similar position at Optus for three years. Although he says he operates fairly independently within AMP, he and his team report into the architecture area of AMP's IT organisation, and he thinks this works well.
"Different people have different recommendations as to where security should fit in. Some say it should sit outside of IT and report up to the CEO through an area like risk management. That was how it was at Optus for a while, but I don't think it makes that much difference as long as you have good management support. Where that support is lacking is where the reporting lines would make more of a difference because you'd need to wield some weight around. But in AMP we have pretty good support, so we could really be anywhere," he says.
While Srede maintains a good relationship with the people who look after AMP's physical security, he says that information security is run quite separately with little overlap between the two areas. The physical security of premises and equipment is also managed separately at telecommunications company PowerTel. However, according to PowerTel's CIO, Geoff Lindner, one of the principal targets of thieves is IT assets because of their commercial value and usefulness.
"We, like every organisation you care to name, have laptops stolen and we have quite extensive rules about how people who have laptops are required to maintain them," Lindner says."They're not allowed to be left on desks or in desk side draws because they're not secure. Rather, there's a special cabinet for storing your laptop, but every now and then we still lose [the odd one]."
- +
Ticked Off at Tick the Box Mentality 04 February, 2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
- +
Adobe launches hosted services, adds Flash to Acrobat 03 June, 2008 09:02:44
Adobe to launch Web site offering users free hosted services for document creation, sharing and storageAdobe this week is set to unveil the next version of its Adobe Acrobat software, which adds support for the company's Flash multimedia technology. The company also plans to launch a new Web site offering users free hosted services for document creation, sharing and storage.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Wireless LANs: Is my enterprise at risk?
Discover the advantages of an open architecture multi-vendor network solution
Everything you need to know about email and web security (but were afraid to ask)
Achieving the impossible: Unlimited application scalability
How to improve employee productivity in small and medium businesses
Controlling storage costs with Oracle database 11g
Delivering the Power of Choice with Microsoft Dynamics CRM
- White PaperJoin Ed Thompson, Research VP, featured analyst firm, Gartner, Inc., and Brad Wilson, General Manager CRM Microsoft Dynamics, for a new webcast, Delivering the Power of Choice with Microsoft Dynamics CRM, available now. Our panel will break down the best practices for getting the most out of CRM and you'll learn key recommendations you can implement in your organization. Additionally, you'll also hear Microsoft's vision for CRM.
- White PaperJoin industry expert Bob Spurzem and Chuck Arconi of Fox Hollow to discover how to reduce Exchange total storage and keep it at a manageable level. Learn how Exchange storage growth can be contained without sacrificing security and accessibility.
- White PaperJoin industry expert Martin Tuip to discover best practice strategy for the archival and removal of .PST files using email archiving. Learn how to ensure long-term email records are there when needed, and reduce the risk to your business and clients.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
CBS website bitten by iFrame hack 02 December, 2008 07:30:00
Russian malware distributors have launched another iFrame attack on a sub-domain of the cbs.com site.TV network CBS has become the latest big name to have it website used to host malware, a security company has reported. - +
Excerpt: Counterterrorism Strategies for Corporations 27 November, 2008 12:36:00
Mike Ackerman calls terrorism "the skunk at the globalization lawn party." His new book lays out 10 principles for how businesses can prepare and respond.Mike Ackerman calls terrorism "the skunk at the globalization lawn party." His new book lays out 10 principles for how businesses can prepare and respond. - +
The 10 Ackerman Principles of Counterterrorism 27 November, 2008 12:43:00
Consultant and author Mike Ackerman's 10 counterterrorism principles for business.Consultant and author Mike Ackerman's 10 counterterrorism principles for business. - +
Survey: Despite Risks, Employees Still Holiday Shop at Work 27 November, 2008 10:02:00
As Cyber Monday approaches, research suggests a majority of workers will use their work computer to shop this holiday season. But despite the continued growth in online shopping, employees and business still don't understand the riskAs Cyber Monday approaches, research suggests a majority of workers will use their work computer to shop this holiday season. But despite the continued growth in online shopping, employees and business still don't understand the risk. - +
Why Cybercrime is Thriving 27 November, 2008 11:52:00
A new Symantec report reveals just how large and sophisticated the online underground economy has grownA new Symantec report reveals just how large and sophisticated the online underground economy has grown.
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 02 December, 2008 11:23:00
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 02 December, 2008 10:09:00
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 02 December, 2008 09:56:00
Virtual magic: HR specialist throws out 40 servers, adds 8TB SAN and saves $100,000 for disaster recovery 01 December, 2008 15:28:00
EXCOM scores back-to-back award trifecta 01 December, 2008 10:46:00
|
||
|
||
|
|
||
|
Data grids and service-oriented architecture
When choosing an SOA strategy, corporations must ensure data availability, reliability, performance and scalability. A data grid infrastructure, built with clustered caching provides a framework for improved data access that can create a competitive edge and sustain customer loyalty. Read on to discover how this can be created within your organisation.
















