- Bank Web sites full of security holes
- SCO Group: Its future is all used up
- Maligned feature being added to IPv6
- I returned my iPhone 3G after six days!
- VPNs: Six burning questions
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
Lack of training institutions for information security management has made IT investment expensive for many organizations in Kenya.
Companies have invested in training IT managers abroad, which is expensive for small and medium-sized businesses in Africa, said James Gathage, lead consultant at QualityPlus, an information-security-management-systems training company.
This has led some companies to neglect information security and management as integral parts of business and organizational growth, he said. So, to reduce costs and make courses affordable, training companies are bringing experts in to train local IT managers.
The reduced cost is expected to encourage government offices as well as corporate entities to start addressing the issue of information security management.
"Today's professionals have learned to travel light, keeping only what's necessary. They do not need to steal the whole computer to destroy the company. A simple flash disk can be used to steal sensitive data from the office," he said.
Gathage sees this security challenge as the main reason government offices have resisted full computerization and digitization of all services.
According to Gathage, government offices have huge cabinets where they file tax records and payroll information -- records that are now being transferred to computers. In a corporate setting, the computer system is likely to have financial data from suppliers and credit-card numbers from customers.
"In the hands of an identity thief, this information is a tool for draining bank accounts, opening bogus lines of credit and going on the shopping spree of a lifetime -- at the expense of your company, your employees and the customers who trust you," Gathage said.
To safeguard client information and corporate espionage, companies are forced to adopt an information security management system (ISMS).
The key concept of ISMS is for an organization to design, implement and maintain a coherent suite of processes and systems for effectively managing information security, thus ensuring the confidentiality, integrity and availability of information assets and minimizing information security risks.
The ISMS makes business sense, because customers want to do business with entities that will not expose their personal information and businesses want to seal all loopholes that may expose them to risks.
If the IT manager is knowledgeable regarding Cisco technology, he would have 2 options. Option 1 - Consult...- Anonymous
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment