Implementing Threats, Risk and Security Audits

People used to close business deals with a handshake.The first step is risk assessment, to identify the most
They looked one another in the eye. Today, more andimportant assets and information: threats and
more transactions are electronic, anonymous and, invulnerabilities are identified; solutions are proposed and
too many cases, fraudulent. Any organization thatrefined; corporate policies are tightened up; roles and
stores or moves important information on an electronicresponsibilities are assigned; standards and training are
network is putting its information at risk. A criminal ondeveloped.
the other side of the world or an apparently loyalThe next step is the creation of a security plan, with its
employee may have the ability to wreak havoc, byown procedures, budget and implementation timetable.
stealing, deleting or exposing confidential information.Once those steps are complete, any new architecture
The Computer Crime and Security Survey, conductedcan be rolled out and new procedures put in place. At
by the Computer Security Institute and the Federalthis point, the new system should be tested from the
Bureau of Investigation, indicates almost two-thirds ofoutside for any remaining weak points.
the large corporations and government agencies itFinally, to maintain system security, security should be
surveyed lost money when their computer securityaudited on a regular basis to keep pace with both
broke down.internal changes and evolving external threats. The
The survey noted that 9 out of 10 respondents hadTRA provides the map, but organizations must make
computer security breaches during the previous 12the journey. Consulting companies have identified
months. Proprietary information worth $170.8 millionfactors that contribute to the success or failure of an
was stolen from 41 respondents. Fraud cost 40IT security project. Senior managers have to support
respondents $115.8 million.the project and demonstrate their involvement.
When only 45 per cent of executives in NorthOtherwise, their staffs will place a higher priority on
America said they conduct security audits on theirother activities.
e-commerce systems, (around the world, fewer thanBusiness and technical experts should both be involved
35 per cent had conducted security audits) it becomesbecause solutions that overburden the enterprise are
obvious that organizations must improve theirnot acceptable. Individual business units should be
defenses quickly.responsible for their own TRA to prevent
The first step in protecting information assets is afoot-dragging during implementation and finger-pointing
Threat and Risk Assessment (TRA). Without thelater. Interestingly, one consultant recommended
information it provides, organizations are in danger ofconducting assessments on a
fixing only what is broken and ignoring potentialdepartment-by-department basis, rather than all at
hazards. While the specifics of a TRA will be unique atonce. The reasoning is that valuable resources can be
each organization, a common methodology provides anarrowly focused, and lessons learned can be carried
starting point.over to subsequent assessments.