« Don't Be The Next CyberCrime Headline! | Main | Finding log gems among the norm in Sendmail »
Speaking to the need for Information Security to evolve, Amrit makes three key points:
He goes on to deliver one of the key answers to responding to these challenges -"Process is as important, actually even more so, than technology -start with process than add technology to support strong process, not the other way around".
This is more than right. It's critical to success. Most security teams we speak to are dealing with three levels of "compliance". First, regulatory (SOX, HIPAA, GLBA...). Second, industry and business (PCI...) and third, process and control. Executing against each of these individually would require an unbelievable and unsustainable effort. The reality is that compliance can be addressed best by starting with processes. It should be a "write once, run everywhere" activity.
This is the primary reason we're not just addressing individual mandates through our LogLogic Compliance & Control suites but also best practices and controls such as COBIT, ITIL and ISO. And, why our platform is a SOA that facilitates sharing of information and intelligence with other applications and systems. In doing so, we're getting directly at Amrit's final point: "Security can no longer exist in a silo or a vacuum, security programs and security professionals must align themselves with the business or face extinction."
Posted November 13, 2006 in LogMatters | Permalink
TrackBack URL for this entry:
http://www.loglogic.com/mt/mt-tb.cgi/104
| Sun | Mon | Tue | Wed | Thu | Fri | Sat |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | ||||
| 4 | 5 | 6 | 7 | 8 | 9 | 10 |
| 11 | 12 | 13 | 14 | 15 | 16 | 17 |
| 18 | 19 | 20 | 21 | 22 | 23 | 24 |
| 25 | 26 | 27 | 28 | 29 | 30 |