Business alignment, security define apps

By Vivian Yeo, ZDNet Asia
Tuesday, August 26, 2008 07:32 PM

SINGAPORE--Tech departments need to focus on both data protection and delivering business value, not simply put in place applications to please business users, according to a consultant.

Steve Lam, manager for technology and security risk services at Ernst & Young, said Tuesday that too often, IT departments have the mentality of creating the applications demanded by users to strike them off their to-do list, without really considering how they might impact business and security. He was speaking at a seminar in the island-state to discuss trends in security, networks and convergence.

According to Lam, "a lot of clients fail their first" attempt at putting in place a risk management framework. It becomes a "compliance for show" exercise as the framework implemented was not being practised or internalized by the organizations, he explained.

Singapore-based Lam also pointed to the failure to learn from previous mistakes, as a stumbling block in risk management. Additionally, the first buffer overflow struck in 1972, but over the years businesses and individuals have continued to fall prey to similar malicious attacks--the most recent being the unleashing of the Storm worm. People simply don't learn, Lam pointed out.

Enterprises, despite having their application developers work on debugging and refining of previous iterations of code, still find vulnerabilities--such as cross-site scripting and SQL injection--in their software. The concept of Web application security existed several years back but is still talked about today, he noted.

It is necessary to tweak traditional "risk and reward" models of spending as much on network defense as data is estimated to be worth, or making it as resource-draining as possible for hackers to steal information, said Lam. New parameters, he added, need to be introduced.

"Businesses need to look at risk and performance as an [integrated] investment portfolio," he pointed out, adding that there should be "centralized" and coordinated control over all related risk initiatives and programs.

Risk management also needs to be initiated from the top echelons of leadership, and be continuously monitored and evaluated, added Lam.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Common ways IT wastes money on development

Web Development

Examples include using developers as support staff and failing to calculate a project's ROI before giving it the go-ahead.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions




Could this be the most critical budget for India?

Blog thumbnail

For business journalists in India, budget time is excitement time. It's like sports journos covering the Olympics. As a newspaper correspondent, I too had my fill of budget-time excitement. But..... by Swati Prasad

Read more »

Tags

  1. attack
  2. bank
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. u.s.
  19. viruses and worms
  20. web