Hi-Tech Security Solutions Hi-Tech Security Solutions
Follow us on:
Follow us on Facebook  Share via Twitter  Share via LinkedIn
   
 























 

Senior executives information security survival kit
1 March 2006, Information Security


Specific information security risks for senior executives

The following examples show how senior executives can be exposed to information security risks:

* Lack of appreciation of what risks are most significant.

* Failure to mandate the right security culture and control framework and set the right security example.

* Failure to embed responsibilities for risk management into the management team.

* Failure to detect where the most critical security weaknesses exist within the organisation.

* Failure to monitor risk management investments and/or be able to measure benefits realised.

* Failure to direct risk management and be in a position to know what residual risk remains.

Questions to ask

* How is the board kept informed of information security issues? When was the last briefing made to the board on security risks and status of security improvements?

* Is the enterprise clear on its position relative to IT and security risks? Does it tend toward risk avoidance or risk taking?

* How much is being spent on information security? On what? How were the expenditures justified? What projects were undertaken to improve security last year? Have sufficient resources been allocated?

* How many staff had security training last year? How many of the management team received security training?

* How does the organisation detect security incidents? How are they escalated and what does management do about them? Is management prepared to recover from a major security incident?

* Is management confident that security is adequately addressed in the organisation? Has the organisation ever had its network security checked by a third party?

* Is management aware of the latest IT security issues and best practices?

* What is industry best practice and how does the enterprise compare?

* Are IT security issues considered when developing business and IT strategy?

* Can the entity continue to operate properly if critical information is unavailable, corrupted or lost? What would be the consequences of a security incident in terms of lost revenues, customers and investor confidence? What would be the consequences if the infrastructure became inoperable?

* Are the information assets subject to laws and regulations? What has management instituted to assure compliance with them?

* Does the information security policy address the concern of the board and management on information security ('tone at the top'), cover identified risks, establish an appropriate infrastructure to manage and control the risks, and establish appropriate monitoring and feedback procedures?

* Is there a security programme in place that covers all of the above questions? Is there clear accountability about who carries it out?

* Is management aware that serious security breaches could result in significant legal consequences for which management may be held responsible?

Action list

* Establish a security organisation and function that assists management in the development of policies and assists the enterprise in carrying them out.

* Establish responsibility, accountability and authority for all security-related functions to appropriate individuals in the organisation.

* Establish clear, pragmatic enterprise and technology continuity programmes, which are then continually tested and kept up to date.

* Conduct information security audits based on a clear process and accountabilities, with management tracking the closure of recommendations.

* Include security in job performance appraisals and apply appropriate rewards and disciplinary measures.

* Develop and introduce clear and regular reporting on the organisation's information security status to the board of directors based on the established policies and guidelines and applicable standards. Report on compliance with these policies, important weaknesses and remedial actions, and important security projects.

This material is extracted from COBIT Security Baseline. Copyright (c) 2004 IT Governance Institute (ITGI). For additional information on COBIT and ITGI, visit www.itgi.org


  Share via Twitter   Share via LinkedIn

Further reading:

  • Authentication critical in cyber ­security
    May 2013, Information Security
    The business world is at war, not only with competitors, but a war to secure access to their information and applications. The unfortunate reality is that while business leaders know they are at war, ...
  • Transnet focuses on data security
    May 2013, Information Security
    Transnet National Ports Authority (TNPA) is a division of Transnet, tasked with controlling and managing all commercial ports on South Africa’s coastline. It is the largest port authority in southern ...
  • The key to fraud prevention
    May 2013, Information Security
    One of the greatest challenges facing organisations is the time-consuming nature of detecting and investigating fraud, which further impacts the financial and productivity losses caused by the fraud itself. ...
  • The future is a secure cloud
    May 2013, Information Security
    Cloud computing is predicted to be the future of the technology world and analyst reports abound on the expected growth of the uptake of these solutions. However, security issues remain one of the dominant ...
  • Secure authentication for company networks
    May 2013, Information Security
    ESET has announced the general availability of ESET Secure Authentication, a two-factor authentication (2FA) software solution for small and medium businesses (SMBs). This application makes use of remote ...
  • Preparation, expectation and ­authentication is key
    April 2013, Technews Publishing, Information Security
    How exposed are South African companies to cyber attacks? Are they an easy target or simply ignorant? Are they doing enough to protect themselves? How serious is this threat to your average company in South Africa and Africa, or is the threat confined to certain types of companies?
  • A conversation about security
    April 2013, Technews Publishing, Information Security
    The person who is probably most in touch with the state of information security in South Africa is Craig Rosewarne, MD of Wolfpack Information Risk and founder and chairperson of the Information Security ...
  • New approach to security
    April 2013, Information Security
    RSA, the security division of EMC, announced the release of RSA Security Analytics, a transformational security monitoring and investigative solution designed to help organisations defend their digital ...
  • Six-month lifespan of technology
    April 2013, Information Security
    In 2010, the South African government declared cybersecurity to be a national security priority. Since then, the country has been victim to trading stoppages at the Johannesburg Stock Exchange because ...
  • Breaking the browser
    April 2013, Information Security
    Critical vulnerabilities in Google Chrome that could leave millions of Web users exposed to risk were demonstrated on March 6th by the winners of this year’s Pwn2Own competition, global IT security firm ...
  • How to be an info-loser
    April 2013, Information Security
    The need to protect valuable business and personal data from hackers, viruses and theft is something that all users are aware of, as cybercrime has become a multi-million dollar industry. However, there ...
  • Strategy for future of business security
    April 2013, Information Security
    McAfee has announced its strategy for building upon Security Connected, the framework in which security products and services work together to safeguard businesses with better protection from new types ...

 
 
 
Search...
Hi-Tech Security Solutions Business Directory


         
Contact:
Technews Publishing (Pty) Ltd
1st Floor, Stabilitas House
265 Kent Ave, Randburg, 2194
South Africa
Publications by Technews
Dataweek Electronics & Communications Technology
Electronic Buyers Guide (EBG)

Hi-Tech Security Solutions
Hi-Tech Security Business Directory (HSBD)

Motion Control in Southern Africa
Motion Control Buyers’ Guide (MCBG)

South African Instrumentation & Control
South African Instrumentation & Control Buyers’ Guide (IBG)
Other
Terms & conditions of use, including privacy policy
PAIA Manual
         
    Mobile | Classic

Copyright © 2012 Technews Publishing (Pty) Ltd. All rights reserved.