Showing posts with label IT Governance. Show all posts
Showing posts with label IT Governance. Show all posts

Monday, June 21, 2010

Digital Consumers and Cloud Computing

I think the following words of Shri N R Narayana Murthy, Chairman and Chief Mentor, Infosys Technologies are very significant and merit attention:

“Digital Consumers are increasingly relying on Technology to make buying decisions…By 2012, 80 per cent of Fortune 1000 enterprises will be using some form of cloud computing services.”

The Dot Com companies crashed in 2000-01 because of poor bandwidth and inadequate security. Today with a quantum leap in bandwidth and a lot of awareness about risk and risk mitigation, online business is at the brink of a boom!

Tuesday, February 23, 2010

Sharks and Coconuts Again!

It was a balmy evening in Balmbay as I made my way to the Airport, replete with all the learning for the past two days at the ISACA-CACS at Mumbai. The learning event was quite useful although my head is still heavy from all the Knowledge/Information/Data/Facts/Opinions that have been crammed into my little brain. Well, I suppose I have to digest it at leisure. After all Knowledge is not about Memory, its about Retrieval, right?

Hugh Penrie Williams began his session with a promise that he came to make us Think, Not Teach.

Surprisingly he used the Sharks and Coconuts example to talk about Risk. But his take is that we should be more worried about Pigs and not Coconuts. I think more people are going to be harmed by speakers giving the Sharks and Coconut analogy than both these hazards put together.

He rightly pointed out that there is no point in talking about Risk unless you "know" more about the "asset" being protected. In an Information Systems Security Concept the more valuable assets are the Data and Applications.

Instead of asking why a disater happened, we should be asking why it didn't happen more often. Then, the good systems and processes in place become obvious. Failures and vulnerabilities are seen with more clarity.

Another quote I loved in this session was,"The average is inconsequential or useless as we are forced to live with the constraints actually imposed on us."

Threats are in the Environment. Vulnerabilities are potential weaknesses in our protective measures. A threat that has exposed a vulnerability leads to an incident.

He mentioned that Risk need not have negative connotation. This is something I've always been telling students in my Securities Analysis programmes. In the last GMCS, a gentleman Mr. Prabhu vehemently argued otherwise. I wish he had been there to hear Penrie Williams!
Risk simply indicates that Anything can happen.

So, what we are really talking here is about degrees of uncertainty. A continuum that ranges from absolute certaintyof occurance of an event (Zero Risk) to to absolute uncertainty of an occurance. A probabilistic approach anchored in Business sense may be the solution.

The post lunch sessions on Cloud Computing and Wirelss Network DSecurity were quite technical thougfh the respective speakers Mardikar and Gibbs de-mystified much.

One unresolved issue in Cloud Computing seems to be the reason for including an entirely privately deployed system under cloud systems as a Private Cloud. Muti Tenancy of Infrastructure/Application seems to be a basic criterion in clouds. Take this away and where is the Cloud in Private Clouds.

A Final Thought:

I have a feeling that ultimately whether its Cloud Computing or IT Governance or Risk Management, or Wireless Network Security, the basic issue is Perimeter level security both at Physical as well as Logical levels. For example Nelson Gibbs on WiFi suggested we keep the Wireless Access Point (WAP) outside the Firewall.

Monday, February 22, 2010

Protecting ourselves from Sharks when the Danger is Falling Coconuts


The Afternoon Speaker at the ISACA-CACS, Eddie Schwartz began by pointing out that the number of people who die on the beach due to Sharks is far far lower than those who die due to falling Coconuts! In his frank and down-to-earth presentation on "Why some Organizations are winning the Cyber War?", he gave a lot of insights on the issues in IT Security due to Cloud Computing.

He says prevention is not really possible as the threats and vulnerabilities in Cloud Computing are too many. Moreover, it is difficult to identify the perpetrators. He suggests Continuous Controls Monitoring and Advanced Threat Detection Systems. We need to be always aware of threats and potential threats to our security systems.

Summary: The solution seems to be a proxyt based ATDS coupled with continuous session monitoring.

The next speaker on Data Loss Prevention and Digital Rights Management was Mark Ames, an Aussie. He put a lot of store by Identity Management which is just french for Encryption and Password Control. The real threat is still from outsiders then.

Sunday, February 21, 2010

IT Governance Issues

I am now at the Hyatt Regency, Mumbai attending the Asia Pacific Control and Securities Conference (CACS) of ISACA. The sessions are on IT governance and security. This blog and the ones that follow do not attempt to report the proceedings but are rather an attempt to document my immediate reaction to what speakers were saying.

In the morning we had Robert E Stroud.

He was speaking about the five traps in IT governance.
He related real life anecdotes about his children and grand-children.
He describes a scene where his car has a microchip that sends a message to the dealer about a fault in the vehicle, who in return responds to the user's complaint. Well, in India we are not so seamlessly connected; Is that good or Bad?

He was also relating a situation where if the server fails on Thanksgiving day, the store fails. This is because all items are bar-coded and therefore not human-intelligible. Is this an IT incident or merely an inability to plan ahead? Why couldn't they have had someone staying over to handle glitches like this? This would have been automatic in India.

He also made the point that Governance is more than compliance. Governance is not a bottom up issue--it has to be top down.

Risk is not necessarily a bad word. You might want to take a risk to actualize a business opportunity. This is a positive acceptance of risk.

His quotations that he puts on Twitter were:

Perception is Reality.

Power Corrupts. PowerPoint Corrupts absolutely.

He also speaks about external consultants who are brought in as a "Solution". He calls it the "Outside-in-trap" and advocates solving the problem organizationally.

He suggests that we should have a Just Enough approach to Governance as over emphasis on Governance may curb innovation.

SUMMARY OF SESSION

The Deadly Sins in IT Governance are

Absence of 1. Definition, 2. Ownership, 3. Measurement, 4. Mutiple Governance System, 5. Automation. A last one, viz., Transparency was added by a participant which Robert agreed should be the First!

Questions were mainly on the Semantics of words like Security, Governanance and IT Governance. The speakers replies were possibly not the last word on this.





Murudeeshwar