| Analysts |
| Conference Providers |
| Trade Organizations |
| Security by Compliance Is No Longer Working according to ISACA |
|
|
| Written by Staff Writer | |
| Thursday, 23 July 2009 | |
|
Security has been and continues to be a growing issue in particular with the growth of cloud computing. According to ISACA, a leading global provider of knowledge, certifications, community, advocacy and education on information systems assurance and security, enterprise governance of IT, security compliance is no longer working. If organizations continue to focus on security by compliance, he argues, the adversaries will continue to win as their attacks become more effective and more damaging. “Compliance can be a good starting point for securing information infrastructure and data if an organization has not put anything in place previously, but it cannot be the end point of the conversation.” “We need to change the fundamental approach to the way enterprises deal with information protection,” Pironti said in his “Information Security 2.0” presentation at ISACA’s conference. “We need to stop thinking about information security and start thinking about information risk management.” Information risk management requires more input from and decisions made by the business, instead of solely by security professionals and regulators. Explaining the difference between the two, Pironti said, “Information security sets the tone for organizations that forces them to put measures in place that may actually end up preventing the business from being successful. Risk management gives the organization the power to make the security decisions that align with its business requirements and then implement appropriate controls.” Another critical change, according to Pironti, is to focus on protecting data and information instead of just technology.“The technology is just a vessel for the data and has little value by itself. By focusing on the data, enterprises will be better prepared for the challenges that they may face from any adversary” Pironti said. In addition to Pironti’s presentation, ISACA’s International Conference also featured the unveiling of Risk IT, a new IT enterprise risk management framework developed by ISACA. The framework will be publicly available as a free download in September. About ISACA With more than 86,000 constituents in more than 160 countries, ISACA® (www.isaca.org) is a leading global provider of knowledge, certifications, community, advocacy and education on information systems assurance and security, enterprise governance of IT, and IT-related risk and compliance. Founded in 1969, ISACA sponsors international conferences, publishes the ISACA® Journal, and develops international information systems auditing and control standards. It also administers the globally respected Certified Information Systems Auditor™ (CISA®), Certified Information Security Manager® (CISM®) and Certified in the Governance of Enterprise IT® (CGEIT®) designations.
Set as favorite
Bookmark
Hits: 649 Comments
(0)
You must be logged in to a comment. Please register if you do not have an account yet.
|
| Fri, Feb 26th, 2010, @8:00am |
| Thu, Mar 11th, 2010, @8:00am |
| Wed, Mar 17th, 2010, @9:30am |
| Tue, Mar 23rd, 2010, @8:00am |
| Tue, Mar 23rd, 2010, @8:00am |
| Mon, Apr 19th, 2010, @8:00am |
| Wed, Apr 28th, 2010, @8:00am |
| Mon, May 17th, 2010, @8:00am |