ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Should IT security be separate from IT?

Maxine Holt Butler Group

Published: 12 May 2006 13:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The IT department faces an enormous range of management issues, of which IT security is one significant aspect. For 2006, security is no longer the most pressing of the IT issues; it does, however, remain a major consideration.

Security affects many aspects of IT – operational, complexity and risks of IT systems and measurement of value, to name just a few examples. Furthermore, the addition of compliance and corporate image into the mix makes the security issues facing the IT department quite extensive.

The selection and implementation of IT security solutions can be an onerous task, alongside the maintenance of these systems. If an organisation had a separate IT security department, this department would be solely responsible for not only the selection and maintenance of IT security solutions, but also for approving the new solutions requested by the IT department and the rest of the business. In this way, all security aspects of a solution are thoroughly tested before implementation (or purchase), thus reducing the risk to the organisation. This responsibility is taken away from the IT department, leaving it to concentrate on fulfilling the organisation's objectives.

However, separating IT security from the IT department can become a company political hot potato if not handled carefully. It requires the IT department to manage the relationship with the IT security department – perhaps this is not something it is willing to do, or able to take on for whatever reason. And if there are no issues with IT security in an organisation, then is it necessary to create a separate IT security department? The fact is that if all IT security aspects are being handled adequately and sufficiently in advance, without any breaches, it is unlikely to be necessary to create a separate department.

In order to determine if separation of IT security from the IT department is appropriate, it is first important to be aware of the IT and business drivers that influence security. The IT drivers include internal and external threats; these threats are not diminishing over time but are getting worse, and the internal aspect (both malicious and otherwise) continues to be the worse of the two. Other IT drivers include service commitments; do the security aspects of a system slow down the responses to unacceptable levels within Service Level Agreements (SLAs)? Other examples include IT complexity, business complexity, auditability, patch management – the list goes on.

The business drivers that influence IT security include accuracy and consistency – ensuring that all business data is processed accurately and consistently without any opportunity for it to be breached. SLAs have already been mentioned as IT drivers, but of course they are also applicable as business drivers, to ensure that the organisation is able to conduct its day-to-day work without fear of security breach. Other business drivers include the protection of the organisation's image – for the likes of Amazon and eBay, this is crucial. Even for companies with a strong high-street presence, such as Argos, security breaches can severely affect brand image.

Compliance is a major driver for IT security, ensuring that key factors are managed, with examples including the control of access to systems and the creation of an audit trail. When all these factors have been reviewed, the extent to which security is ingrained in the culture of the IT department should be fairly clear. If IT security...

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
117 out of 275 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments