Business alignment, security define apps

By Vivian Yeo, ZDNet Asia
Tuesday, August 26, 2008 07:32 PM

SINGAPORE--Tech departments need to focus on both data protection and delivering business value, not simply put in place applications to please business users, according to a consultant.

Steve Lam, manager for technology and security risk services at Ernst & Young, said Tuesday that too often, IT departments have the mentality of creating the applications demanded by users to strike them off their to-do list, without really considering how they might impact business and security. He was speaking at a seminar in the island-state to discuss trends in security, networks and convergence.

According to Lam, "a lot of clients fail their first" attempt at putting in place a risk management framework. It becomes a "compliance for show" exercise as the framework implemented was not being practised or internalized by the organizations, he explained.

Singapore-based Lam also pointed to the failure to learn from previous mistakes, as a stumbling block in risk management. Additionally, the first buffer overflow struck in 1972, but over the years businesses and individuals have continued to fall prey to similar malicious attacks--the most recent being the unleashing of the Storm worm. People simply don't learn, Lam pointed out.

Enterprises, despite having their application developers work on debugging and refining of previous iterations of code, still find vulnerabilities--such as cross-site scripting and SQL injection--in their software. The concept of Web application security existed several years back but is still talked about today, he noted.

It is necessary to tweak traditional "risk and reward" models of spending as much on network defense as data is estimated to be worth, or making it as resource-draining as possible for hackers to steal information, said Lam. New parameters, he added, need to be introduced.

"Businesses need to look at risk and performance as an [integrated] investment portfolio," he pointed out, adding that there should be "centralized" and coordinated control over all related risk initiatives and programs.

Risk management also needs to be initiated from the top echelons of leadership, and be continuously monitored and evaluated, added Lam.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Windows Server 2008 iSCSI multiple connected session modes

Enterprise Servers & Storage

For administrators using Windows Server 2008's iSCSI initiator, selecting the right connection policy is critical. Rick Vanover explains the options for the ease-of-entry storage protocol.


Read more »


 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




NUS Enterprise: An 'incubator without walls'

Blog thumbnail

Almost everyone has had dreams of owning their own shop, but most of us know also that it takes a fair amount of resources to open a new business, and..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web