Just got the IEEE Spectrum Magazine July 2011 issue in the mail yesterday. When I started reading it, I noticed a short but interesting article on page 8 in the "Spectral Line" column by Robert N. Charette. The article titled as "More Cyberattacks or Just More Media Attention?" I found the following parts from the article interesting:
"The Internet was not built with security in mind. Regrettably, most IT systems and application that connect to the Internet were not developed with security in mind either, nor has there been much incentive to do so."
In my opinion, this statement is right on. It is unfortunate that majority of organizations out there are still dealing with proper implementation of fundamental security controls. I recognize that there are pretty sophisticated attacks and intrusions going on "out there" as well. However, I still believe that a good percentage of organizations are still struggling with implementing basic security controls. On the other hand, perhaps, the management at those organizations are taking way too much risk with respect to security. I know that nothing comes free and every security control have a price tag. However, these days, consequences of security incidents are very serious. Sometimes, a security incident can create some much damage at the company's reputation and that can lead to a path to complete collapse for the company. This brings the importance of having a management with good understanding of risks associated with not implementation certain security controls. ISACA's RiskIT framework comes to my mind as a resource to educate the management about risk.
The article ends with the following two sentences:
"...cyberattacks are just the risk of doing business. Sadly, only when the risk of cyberattacks becomes unaffordable will cybersecurity be taken seriously.
I believe that the risk of cyber attacks for some organizations has already become unaffordable. The management for the organizations in the industries like banking, security, government should pay careful attention to the risk with respect to the cyber attacks.
The complete article can be found at this link: http://spectrum.ieee.org/computing/networks/more-cyberattacks-or-just-more-media-attention
P.S. Although it might be redundant but I still would like to mention that IEEE creates such a high quality content within its publications. I am a proud member of IEEE. Way to go, IEEE...
No comments:
Post a Comment