governmentnews.com.au

People are still 'weakest link' in security defence

Published on Fri, 03/02/2012, 02:55:31

|

By Jo Stewart-Rattray, director of information security for national accounting firm RSM Bird Cameron; the international; the international vice president for global information security governance industry association ISACA; and chair at ISACA’s leadership development committee; member of its COBIT for Security Taskforce.
 
While public sector agencies confront security risks from the cloud to social media in 2012, their greatest challenge is to build an intentional culture of security among staff warns an international expert in information security.
 
We have to be aware of that fact and the means eternal vigilance is the price paid for the role of CIO.
 
The responsibility for security within a public sector agency – or any organisation – could not be compartmentalised.
 
The truth is security is everyone’s responsibility and the buck has to stop somewhere, which is with the CEO or with the board in a corporation.
 
Public sector agencies demonstrated a broad range of responses to security challenges. Some agencies are at the forefront while others lag in the rear.
 
South Australia’s Office of the CIO has rolled out a revised version of its Information Security Framework to the public sector, which has provided State Government agencies with guidance.
 
Also in South Australia, public sector agencies have designated Information Technology Security Advisors (ITSAs) – a position which goes by other names in other states – whose role is to advise the business on issues relating to information security.
 
The various offices of the Auditors General around Australia regularly come out with reports that lambast some agencies.
 
For example, the Auditor General in WA makes no bones about reporting how many agencies are successful in the security area and how many have ‘room for improvement.
 
There are many legitimate reasons why an agency may not be at the forefront with security methodology.
 
These can range from budgetary constraints or changes to their organisational structure to the commencement of, or changes to, outsourcing services or bringing shared services in-house.
 
Each agency had different information security requirements and priorities depending on their line of business and the types of content they retained.
 
For a new chief executive going into an agency, the first step towards information security is to ascertain the security position of that agency.
 
This involves asking any ITSA or equivalent roles as well as the CIO: Where we are up to?
 
If an information security review has been undertaken recently, read it to see what risks were identified and what recommendations were proposed and which of those were implemented.

Add your own comment
1,148


Your Vote

What are your procurement priorities for 2012?

IT implementations

Infrastructure

Green implementations

Security for property

Ugrading fleets



CONFERENCES & EVENTS

SPLASH! Pool & Spa Trade Show

25-26 July 2012, Jupiter’s Casino & Hotel

Read More »

AHPM Congress

13-14 August 2012 Doltone House, Sydney www.ahpmcongress.com.au

Read More »
COURSES & TRAINING

Contract Governance Education Programs

CPLi is a specialist provider of professional contract governance education programs and consulting services.

Read More »

Government funded business and management qualifications.

ITCC has a range of business and management qualifications, some of which are government funded. If eligible, Federal Government funding will cover the total cost of some of the below qualifications for you or your staff.

Read More »

Take the Pain out of Managing your Training

Partner with mytraining.net we help take the headache out of multi-quotation requirements & streamline training reservations

Read More »
SECURITY PROFILE

ADT Security Solutions

ADT Security can provide Government Security solutions such as Grade A1 monitoring, Type 1 certified installation and monitoring.

Read More »
GREEN PROCUREMENT

Zero emissions sweeper

The Green Machines 500ze is a Lithium-ion powered vacuum street sweeper, heralds a significant step in the drive for reduced carbon emissions and improved air quality.

Read More »
NEW PRODUCTS

Fujitsu General launches AIRSTAGE VR-II heat recovery system

Bringing its expertise to life at ARBS, global air conditioning specialist Fujitsu General has launched its AIRSTAGE VR-II heat recovery system.

Read More »

New Cat M Series

Now factory-fitted with AccuGrade-ready components – at no extra cost.

Read More »

Isuzu - The One For Low Emissions

Scratch the surface and it's easy to see that not all truck manufacturers are created equal in terms of exhaust emissions.

Read More »