The science of information security

1 April 2016 Conferences & Events, News & Events

Information security is rarely achievable through the random application of IT security components. It is about understanding the value of an organisation's information assets, determining the risks to the information and the systems that contain it, and designing appropriately scoped solutions to remove or mitigate the risks.

So said Steve Jump, head: Corporate Information Security Governance at Telkom, who will be presenting on the science of information security at the ITWeb Security Summit 2016, at Vodacom World from 17 to 19 May.

He says, as with all such exercises, to measure how well information security is done requires a model with metrics and an understanding of what the business considers to be its main objectives.

"Although this is often seen as an engineering problem, we look at this process as obtaining knowledge about the organisation, its purpose, its staff, its products and its information assets that go beyond the technical. We consider this to be the science of information security."

In terms of what South African businesses are doing wrong when it comes to information security, Jump says the easy route is looking at what everyone else is doing, and buying or renewing the same systems that have always been in place.

It is also easy to continue spending money on the support, maintenance and operation of these systems, because not to do so would make things harder.

"Because of this, if an organisation has not reviewed the function of technical and procedural information security systems against its own current business threats in the last 24 months, it is very likely that it is paying for systems that are not being fully used, and are not protecting the assets that the business expects them to."

According to Jump, any security tool that is tested on a system will discover a 'new threat'. "As a security executive you are responsible for making sure that the cost of detection and removal of that ‘new threat' is actually a real reduction in your business' risk profile, and that the investment in its acquisition and use is appropriate to the benefit."

He says merely having the latest and fastest security systems does not automatically mean that the organisation is safe, but if there is an understanding of what is being protected, the right resources can be applied to the right problems. "Not only will that help you manage the cost of your security solutions, it will help you to manage their operation."

ITWeb Security Summit 2016

Steve Jump from Telkom will be presenting at the 11th ITWeb Security Summit 2016 on 17 and 18 May. He will discuss the science of information technology and how you can prove that your current security system and process is working for you, or not. To view the full agenda, click here. To register, click here





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Risk management: There's an app for that
Editor's Choice News & Events Security Services & Risk Management
Zulu Consulting has streamlined the corporate risk management process with the launch of Risk-IO, a web-based app designed to consolidate and guide risk managers through the process, monitoring progress as one proceeds.

Read more...
Integrated information platform for risk management
Editor's Choice News & Events Security Services & Risk Management
Online Intelligence recently launched version 7 of its CiiMS risk and security platform. Speaking to SMART Security Solutions after the launch event, the company’s Arnold van den Bout described the enhancements in version 7.

Read more...
Unlocking Africa's AI potential
Editor's Choice News & Events AI & Data Analytics
Africa's AI market is set to grow exponentially; by investing in AI education, training, and ethical practices, African nations can harness the power of AI to transform the continent and create a brighter future for its people.

Read more...
Entries to southern Africa OSPA Awards now open
Technews Publishing Securex South Africa Editor's Choice News & Events
The southern Africa OSPAs are part of a global awards scheme that recognises and rewards teams, individuals and organisations for their commitment and outstanding performance within the security sector.

Read more...
Securex has moved to June
Technews Publishing Editor's Choice News & Events
Following the formal announcement of the date for South Africa’s national election, 29 May 2024 , which happened to be in the middle of the planned dates for Securex South Africa, Securex will now take place from 11 – 13 June 2024 at Gallagher Estate in Midrand.

Read more...
Africa Online Safety Platform launched in SA
Training & Education News & Events
Impact Amplifier, with the financial support of Google.org, launched its African Online Safety Platform (AOSP), a platform providing a rich repository of research, education content, funding opportunities and ways to seek help after an online crime.

Read more...
International access manufacturer sets up shop in SA
Technews Publishing Access Control & Identity Management News & Events Products & Solutions
The South African security market can always use some good news, and this year, STid has obliged by formally entering the South African market, setting up its main office in the Boomgate Experience Centre in Roodepoort, Johannesburg.

Read more...
Enhance the safety of lithium batteries
Power Management News & Events
One of the processes that can hamper the functioning of lithium batteries is an internal short circuit caused by direct contact between the cathode and anode, but a solution may be at hand.

Read more...
Beagle Watch adds fire to its portfolio
Editor's Choice Fire & Safety News & Events
Beagle Watch Armed Response and FIRE OPS SA announced the enhancement of the two companies' combined service offerings to provide professional fire safety services to Beagle Watch clients and Johannesburg residents.

Read more...
ASSA ABLOY acquires Amecor in South Africa
Amecor Editor's Choice Perimeter Security, Alarms & Intruder Detection News & Events
ASSA ABLOY has signed an agreement to acquire Amecor, a well-known South African manufacturer of security communication equipment in the South African security market and beyond.

Read more...