October 07, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Business Activity Monitoring Syndicate This
Print this article    Email this article    Talk Back!    Write to Editor
But Where's the Security?
06/02/2008
By Dan Gray, VP of Technical Strategy, Solutionary, Inc. and Jon Heimerl, Director of SecurCompass Development, Solutionary, Inc.

The latest buzz in Information Technology is IT-GRC, hyped by vendors and abetted by analysts as the next great wave of IT management solutions.

ADVERTISEMENT
Our Popular Webinars
Insurance: Discovering the Missing Link of Business Architecture
BPM for Insurance: Are You Staying Competitive?
Enterprise Service Bus: The case for 'e'SBs
Know Thy Enterprise: Increase Effectiveness With Business Activity Monitoring (BAM)
How Secure is Your Data? Learn about PCI Solutions
You Can Implement Today.
More Webinars

GRC stands for Governance, Risk, and Compliance, and IT-GRC packages claim to be able to integrate these three domains under one roof. The underlying promise is that finally the board and management can get control of IT and appropriately govern and manage the IT operations to ensure that enterprise risk management goals are met. Regulators and business partners will be kept satisfied by the organization and its partners in regards to compliance.

But just as the best financial management systems and a bevy of auditors have not stopped the flow of financial misconduct by motivated perpetrators, this promise will also fundamentally miss the mark without directly addressing the issue of security.

As evidenced most recently in the Hannaford data breach incident, where the trust of an estimated 4.2 million payment card holders was violated through a security flaw, an organization can have a risk management program and a compliance program and still not be secure.

According to public statements, Hannaford used an IT-GRC package to manage their risk and compliance program, had undertaken and passed outside assessments and audits, and from all outside appearances, had been doing "the right things." But, if having a risk management and compliance program nets the organization a very public and costly data breach, exactly what is the point? How many dollars spent on those programs would have been better spent on addressing the fundamentals of security?

After the breach was publicized, Hannaford president and CEO Ronald C. Hodge said in a statement: "We have taken aggressive steps to augment our network security capabilities."

Section 4.1 of the PCI Standard reads, "Encrypt transmission of cardholder data across open, public networks," stating further, "Sensitive information must be encrypted during transmission over networks that are easy and common for a hacker to intercept, modify, and divert data while in transit." Is it arguably "reasonable" to believe that internal networks are significantly less vulnerable to attack than public networks? Yes. Is it actually true in the real world of the large distributed network? Probably not.

Page 1

More Top Stories
Identity Networking: Where Security and Compliance Meet Gold Club Protected
Do You Need BPM for SOA Governance? Gold Club Protected
Insurance Business Drivers and Top 10 Influencers Gold Club Protected
Five Ways BPM Enables Enterprise Governance Gold Club Protected
Get Smart About Database Security Gold Club Protected
Business and IT Alignment: A Road to Nowhere? Gold Club Protected
More Top Stories
Related News
Latest CA Wily Application Performance Management Solution Optimized for Larger, More Complex SOA and Virtualized Environments
Aster Data Systems Releases nCluster 3.0 to Monetize High Volume Business Data
Symantec Introduces IRM Strategy for Securing and Managing Unstructured Information
More News
Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
Enterprise Service Bus: The case for 'e'SBs
Date: Oct 16, 2008
Time: 14:00 PM ET
(18:00 GMT)

REGISTER TODAY!
BPM for Insurance: Are You Staying Competitive?
Date: Oct 28, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Archived Webinars | Upcoming Webinars
  IBM Smart Strategies for Web 2.0 Newsletter

Is it possible for business users to design their own applications? Are Web 2.0 methods and mashups ready for the rigors of enterprise-scale...Learn More

ebizQ also recommends
 FILLING HOLES IN THE SOA STACK WITH RUNTIME GOVERNANCE
 SOA Middleware: An Agile Framework for Fast, Flexible, Low-Risk Service Deployments
 Multi-Enterprise Integration and Managed File Transfer
 How to Structure your First BPM Project to Avoid Disaster
 How Social Computing, Team Collaboration, and Enterprise Content Management Drive Competitive Advantage
More White Papers

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map

Live Chat