ITIL takes on security management role
Implementing ITIL process improvements said to mitigate enterprise risk
By
Denise Dubie
,
Network World
, 12/06/2007
- Share/Email
- Tweet This
- Print
Long touted for streamlining processes and reducing operating costs, the ITIL best-practices framework also helps mitigate
enterprise risk, say its adopters.
This week at the IDC IT Service Management and ITIL Forum in New York, analysts and enterprise ITIL adopters discussed how
process improvements now are providing security benefits. A November survey of more than 300 companies by IDC revealed that
security had surpassed improved availability and lowered costs as a main driver for adopting the best practices laid out in
ITIL.
Specifically, some 56% of survey respondents indicated security as a motivation for ITIL, close to 50% said they wanted to
lower costs and about 47% thought ITIL would help improve availability at their organizations. More than 45% said problem-solving
was a driver for rolling out process improvements, and nearly 45% indicated that reducing errors was a top driver for ITIL
adoption.
"Any type of process standard going forward will give you a chance to set policies and processes around security," said Fred
Broussard, research manager of PC and device management software at IDC, during a presentation at the one-day event, which
drew more than 100 attendees. "For instance, you can ensure only authorized users gain access and better guarantee unauthorized
access doesn't happen."
The survey response might indicate a growing need among enterprise companies to better secure corporate data and information,
considering processes around security information management (compare products) have been incorporated into ITIL Version 3, which was released earlier this year. Dave Howard, national business technology manager for Toyota Financial Services (TFS) in Torrance, Calif., explained to forum attendees
how security policy creation and governance has been incorporated into the upgrade and how TFS has created a Security Center
of Excellence and an Office of Privacy that align with some of the recommendations in the best practices framework.
"It is important to do security management," Howard said. He also explained how TFS incorporated security into his service
design package process, in which models of a service are built and multiple criteria are taken into account. For instance,
throughout the process of creating a service, his team has to determine the service's ROI, as well as which security requirements
are necessary to deliver it. "For every new release we plan to push out into the environment, we also create a risk model,"
he said.
ITIL may not provide the external protections of a firewall, but it can go a long way in securing internal resources and preventing
data breaches that have become commonplace among U.S. companies.
"Security [can] be the motivation for doing some of these processes, such as patch and change management, for instance, because
improving processes will make security work better in situations such as access controls," said Tim Grieser, program vice
president of enterprise system management for IDC.
In addition, according to enterprise companies using ITIL, security and risk management could be an easier argument to make
when trying to get executive buy-in for adopting ITIL. The ROI for process improvements can be ambiguous and not realized for quite some time, so putting an executive's mind at ease with talk of reduced risk may
be the better way to go.
Partner Content
Blue Stripe Software
www.bluestripe.com/
Improving Application Performance Troubleshooting
Diagnosing why an application is slow is hard, at times taking days or weeks to isolate and resolve. This paper explains the challenges involved using current management tools, provides a 'wish list' for application management and analysis, and explains the need for an application system-wide approach that monitors entire applications, not components.
Download Whitepaper
Virtual Vigilance: Managing Application Performance in Virtual Environments
This paper highlights the impact of virtualization on application performance. "Managing Application Performance in Virtual Environments" states: "Best-in-Class organizations are predominately taking actions around improving visibility across both physical and virtual systems, assessing the business impact of application performance and understanding interdependencies of applications in virtualized environments."
Download Whitepaper
Application Service Requests: The Missing Link for Pragmatic ITSM
Forrester Research analyst Glenn O'Donnell and BlueStripe co-founder Vic Nyman discuss a breakthrough approach to application problem management. Learn the new approach for ITSM problem management, which provides: Rapid isolation of application slow-downs to specific components for quick problem resolution, 24/7 monitoring for proactive notification of potential issues before end users are impacted and much more.
Register for Webcast
Comment