Newsletter:

Skip Navigation LinksHome > News > Security > Risk policy needs rethink

Risk policy needs rethink

By Phil Muncaster
3 July 2006 09:20AM
Tags: risk | policy | needs | rethink

Firms should take a broader view when assessing their security needs,
according to experts.

Firms’ current risk analysis methods lack consistency and could harm their security policies and relationships with business partners, a leading security consultant warned last week.

Speaking at the SecureLondon event hosted by certifications organisation ISC2, Paul Hansford of Insight Consulting said that most firms fail to distinguish between threats and vulnerabilities, and sources and types of threats.

The BS 7799-3 standard goes some way to standardise risk-analysing practices, said Hansford. But he argued that a more definitive process and a formal risk assessor role are needed. “IT security or business risk managers do this job currently but it seems to me there are particular skills required to perform risk analysis, and that’s not reflected in the industry,” he said.

Also at the event, Howard Schmidt, president of R&H Security Consulting and former White House IT security advisor, warned firms they need to address a “new generation” of security weaknesses enabled by peer-to-peer (P2P) networks on the systems of third-party contractors and business partners.

“I’ve seen thousands of documents containing internal administrative passwords, which are now being shared throughout the world,” Schmidt warned. “P2P search strings we’ve identified show criminals are actively seeking these documents.”

Copyright © 2008 IT Week

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch



Product Reviews

Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Star Rating
The Symark PowerBroker is a policy-driven, privileged access control application.
Star Rating
The Symark PowerKeeper is a hardened appliance. It comes with a sealed operating system that provides a...
iTnews 2009 Job Survey

TopTopics
(7276) -  top
(3141) -  microsoft
(2311) -  broadband
(2210) -  content
(2150) -  company
(2118) -  data
(1927) -  terria
(1863) -  isp
(1811) -  nbn
(1720) -  telstra
(1712) -  filtering
(1581) -  internode
(1538) -  voip
(1439) -  centre
(1148) -  consumers