TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
News Archive

Info-risk Afterthought

by Msecadm4921

Despite awareness of the information security risks associated with outsourcing projects and well publicised cases of data loss or theft, many companies still ignore the potential problems until it is too late.

That is the warning highlighted by the Information Security Forum (ISF) โ€“ an organisation with some 300 business and public sector members from around the world.

โ€œThe potential to cut significant costs and increase speed to market clearly make outsourcing and offshoring an attractive proposition,โ€ says Simone Seth, author of a new report published by the ISF. โ€œBut without the right level of security expertise from the outset to fully identify information risk, there will always be important gaps in the business case. If the necessary controls are not budgeted or put in place to mitigate the risks, it can have serious consequences and even threaten the long term success of the outsourcing project.โ€

The ISFโ€™s research claims that information risk management is often integrated as an after-thought, and information security professionals become involved too late in the lifecycle. This can often be explained by a lack of awareness at the highest levels and a failure to understand the importance of information risk management through all stages of an outsourcing project.

โ€œFailure to involve information risk managers at the start of a project and through its lifecycle increases the enterpriseโ€™s exposure to risk; whether itโ€™s data theft, information leakage or disputes that may arise from questions of ownership of intellectual property,โ€ says Simone Seth.

Information mangers need to identify all outsourced processes, operations and technology and agree business criticality levels through all four steps that comprise an outsourcing lifecycle: Prepare, Implement, Operate and Review. Information risk managers are also able to add contractual clauses that relate to information security regulatory requirements and offer additional protection from a legal standpoint. It is also important to understand regional compliance requirements and regulations as well as the wording of contractual terms to prevent future disputes over the ownership of intellectual property and the transfer of data.

Typical risks at implementation and operational stages that can occur if the right controls are not effective, include fraud, data theft or hacking that can lead to data loss and confidentiality breaches.