|
Day 3/ Session
Defenseless defense
George Jason, Security Specialist, India & Middle
East, Spectrum talked about IT and defense and the challenges involved thereof
Jason
started off by talking about IT and Defense and how the increased dependency
on Information Systems had led to the creation of a need for a long term and
failure proof system for securing every form of Information Asset. The theft
of Information can prove disastrous for a company, he said, adding that the
challenge was to launch new business models or products, corporate restructuring,
mergers & acquisitions, changes in the operating environment, rapid growth,
increased customer requirements, RoI and efficiency etc.
Risk arises from many factors. Theres change in systems, the rising incidence
of people threats, changes in the IT and non-IT environment, exposure to new
trends, technology adoption, changes in people, products and processes, failure
to comply with regulations, misuse of funds etc. The countermeasures that a
company could resort to included implementing a secure network, tightening physical
security, deploying firewall, anti-virus, IPS etc, implementing processes and
policy, educating employees, setting up a DR site, hardening systems, et al.
Spectrum offers services such as integrated audit like HIPPA, ISO27001, ISO20000,
PCI-DSS, etc; Vulnerability Assessment & Penetration Testing; Wi-Fi Audits,
Forensic Investigation, Web audits, Physical Security Audits, Infrastructure
Audits, Datacenter Audits, Network Design Audits, VoIP Audits, Customized Training,
Ethical Hacking and Basic Information Security Awareness.
Jason talked about how threat vectors had evolved over the years from being
isolated incidents of vandalism and a nuisance back in the 1980s to serious
cyber crime in the past few years. He described what an IT Audit would deliver
in terms of finding the level of risk to which an organization was exposed to,
whether or not it adhered to Industry Best Practices, Identify vulnerability
& threats, ensure that appropriate controls were in place to prevent exploits,
comply with law, standards and regulations etc.
|