Error » Security Error » Security News » Comsec Consulting Outlines The Challenges And Provides The Guidance

Security News The Latest Computer Security News

Post New Thread Reply
  Comsec Consulting Outlines The Challenges And Provides The Guidance
LinkBack Thread Tools Display Modes
Old 21-May-2008, 05:16 AM   #1 (permalink)
Fixed Error!
 
newsprovider's Avatar

Posts: 140
Join Date: Mar 2008
Rep Power: 1 newsprovider is on a distinguished road

IM:
Default Comsec Consulting Outlines The Challenges And Provides The Guidance

Comsec Consulting Outlines The Challenges And Provides The Guidance For Businesses To Stay Ahead Of IT Governance, Risk And Compliance
Comsec Consulting, a leading information security consulting firm, today presented valuable knowledge and real-life advice on the challenges faced by businesses to manage and stay ahead of IT governance, risk and compliance (GRC).
Addressing fifty senior IT security professionals from blue-chip companies, Roy Harari, Managing Director of Comsec UK introduced the sessions by addressing the trends and drivers from the old pure IT security to overall risk and compliance management.
Nissim Bar-El, Comsec’s Chief Executive Officer and Chairman, highlighted the demands of GRC on any business, while explaining the complexity of this issue and the challenge of actually integrating GRC with Information Security. According to Mr. Bar-El, companies today are juggling the challenge of GRC with the numerous, existing GRC solutions, as well as with ongoing Information Security risks and requirements.
Also speaking at the event was Lord Erroll, spokesman for the House of Lords Science and Technology Select Committee’s report on personal internet security. Lord Erroll highlighted the anecdotal way in which governmental rules and regulations are being referred to and relied upon as definite measures when it comes to securing information online.
He said, ‘The issue of IT security is complex. There are rules and regulations to adhere to, but the IT professional is still unsure of their role or their requirements to ensure their company’s compliancy. Cybercrime and its implications on businesses are still not fully understood, or taken seriously at a governmental level, even in the wake of such serious data loss incidents as reported by the media. The government needs to take responsibility and put into place a serious provision of support and incentive guidelines, including technical information, for all UK businesses. The future lies in governance (not control) and incentives; in new and evolving encryption and authentication technology and in groups committed to cyberwarfare, such as the CPNI (Centre for the Protection of National Infrastructure).’
Henk Van der Heijden, senior manager at Comsec Consulting, provided the conference with an overview of compliance and defined it as the risk of legal or regulatory sanctions; material financial loss or loss to reputation a company may suffer as a result of its failure to be compliant. Simply put, compliance enables companies to assure the integrity and confidentiality of their data.
Mr. Van der Heijden said, ‘The first step for UK companies is to identify the rules, regulations, laws and policies applicable to their company, then breakdown the IT requirements and control objectives, ensuring that there is no duplication of IT requirement to fix one problem. Map out the business processes, use existing frameworks and monitor, analyse and report on compliances needed. Overall, be clear about what they are trying to achieve, set clear reporting and responding lines and define responsibilities.’
Mike Popham of InfoGov, presented an integrated approach to GRC as increased competitive pressures, ethical and financial standards, accountability demands, increasing regulations and demands from stakeholders. He also outlined the different approaches to gaining compliance as: asset based risk assessment; threat modelling; technical auditing; dependency modelling and gap analysis, but enforced the need for companies to be more pro-active, bring top-level management onboard and set objectives with achievable results.
Addressing the payment and financial services industry, Peter Warner, Comsec Adviser and former Vice-President of Fraud & Security at Europay/MasterCard, revealed the extent to which hackers will go in order to retrieve credit card details and steal identities.
Mr. Warner said, ‘Total UK issued credit card fraud has increased by over 25% in 2007, compared to 2006. Card Not Present Fraud accounted for over half of all fraud and this fraud type alone increased by more than 36% in 2007. Fraud abroad saw a 77% rise year on year. This is for a number of reasons. Some merchants may be to blame, as they are not all storing data in compliance with the Payment Card Industry Data Security Standard (PCISS), formulated by the five largest Credit Card companies (American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc.) in order to enforce a security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures, and thus regularise the multiple information security issues standing before credit card merchants and vendors worldwide. Fraud losses per card compromised can be as much as £500 or more and in addition those responsible for the breach face penalties from the card associations and compensation fees payable to the card issuers.
Mr. Warner continued, ‘PCI provides an organisation with an ample opportunity to review the security strategy and controls which can deliver competitive advantage, maintain a positive corporate image and safeguard consumer confidence. Non-compliance can result in damaged reputation to the brand; potential loss of consumer goodwill; financial liability for fraud/chargebacks; fines, penalties and potential legal liability.’
GRC is a challenging trend in the Information Security market, combining various standards, schemes and complex controls all together. There is a lot of confusion on what exactly GRC is and what sub-components to consider when establishing a GRC programme. Professionals should be engaged in the establishment of such a programme, providing experience with adaptation to the specific circumstances of each company. There are quite a few common issues that should be noted before conducting a GRC program. Comsec’s event – “GRC Made Easy” – focused on providing professional insights and practical guidance on some of the key issues when facing GRC.
newsprovider is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 10:31 AM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227