Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, March 02, 2008

Security Skills Lacking

Apparently Security skills of the IT work force lacks generally. This is not surprising as for the most part many organisations where I work there is a lack of understanding of IT security. The government departments are very aware, generally have good policy and practise in place but I have seen many stupid breaches of good practise due to poor policy and procedures. This is where the problems often lie and its not the practitioners, who are struggling to do there job but the management who fails to understand many of the ramifications as they do not well understand the problems they are being faced with at the coal face.

This is a common problem that many parts of IT face. Management ever come up to you and say "can you sort this out for me it shouldn't take more than a few hours." Well this lack of understanding of IT from our managers is what is leaving the organisations exposed to breaches.

Clearly many managers do not understand IT law, I find this a terrible oversight that leaves many companies exposed to poor outcomes when there is a failing of there IT policy and procedures.
Recently I was doing some work on a clients site and they had me sign a piece of paper for internet access about acceptable use. It would now be considered that for that organisations they will be covered against a misdemeanour. My legal studies would lead me to the conclusion that they are likely on shaky ground, for a few reasons they have not clearly identified what are a couple of items open for interpretation. what is offensive and what is acceptable use. Now maybe another time they might just put me on a induction course that will clearly outline these, however until that is clearly stated then what may be considered offensive by the organisation may not be yours or mine interpretation.

It is these problems that management have about IT and security that are leaving the IT practitioners hanging out as without this being understood how do they understand the firefights the practitioners are wrangling inside and outside the organisations. If they can't understand this how do they get to a place where they have sufficient skills. Offering training will be good, but how does it benefit people. Does a new Checkpoint course really help solve the problem or should we look deeper at other types of training to take people out side the box to solve the problems. I certainly think a lot of management needs to go there.

See ya round

Peter

Security skills of IT workforce lacking, survey finds - Network World

Wednesday, August 08, 2007

WSJ did a real fine thing

An article found recently on Wall Street Journal about a series of ways to circumvent IT to get stuff done, or bypass IT controls, seems at first as a real problem for IT departments, the way the artical is written is clearly an attack on the IT teams authority.
We to that I say boo hoo, to all the CIO's out there if this is a problem you haven't been doing your job, you clearly failed in a major part of your job description and that is education, and understanding of your user(client) requirements.
Firstly let me remind you you are in a service industry, with a requirement for providing service to your clients and if this is now suddenly the worst thing in the world then you are clearly lacking in part of your job. You haven't been providing service. Why are you users so excited about this revelation that there are ways to get your job done, because you have tried to close everything up because that just made your job easier, not theirs.
If this article is a problem to you then I would be having a very defined meeting with this article as the agenda and the intention that no one is leaving until you have some sort of plan to deal with it. If you keep hiding with your head in the sand about this your users are going to be your greatest nightmare.
If SOX or HIPAA or any other similar compliance program is going to have to be dealt with you clearly need an education program and maybe fast.

A simple plan might be:
  • Take each one and define why user might want to use that element
  • determine if legislation affecting your organisation is a related to that element
  • educate your users about the risks or why legislation disallows their usage
  • work to implement things that will improve, cant have people donloading any software, but we might be able to run some evaluation program via the corporate wiki to determine the needs and requirements and find a solution.
  • implement slowly the allowable things and implement those education plans


I think for quality IT operations this is a not a problem as their users are aware of the issues and have qualiy solutions in place for remote work etc.


To the rest its time to get your act together



See ya round

Peter




Powered by ScribeFire.