Showing posts with label Compliance. Show all posts
Showing posts with label Compliance. Show all posts

Secure Government Networks - 5 Points For Success in Gaining Compliance and Connection


"The world is changing around us at an incredible pace due to remarkable technological change. This process can either overwhelm us, or make our lives better and our country stronger. What we can't do is pretend it is not happening." Prime Minister Tony Blair on commissioning the Transformational Government strategy.

To survive in this era of accelerating technological change, and to implement the edicts of the Transformational Government strategy, every public sector organisation will have to undergo fundamental technology-enabled change. This article provides a five-point check list for senior managers responsible for developing and delivering a successful Transformational Government change programme.

Ensuring that an organisation can satisfy the necessary information security requirements to enable it to be a component part of joined-up government, requires consideration that will inform budget and strategy, reshape organisational process and procedures, and redefine culture and working practices.

As a guide to those responsible for their organisation's information assurance and implementation of the Transformation Government agenda, this article provides a five-point check list to provide a basis for ICT-enabled organisational change.

Point 1 - Be fully appraised of current Government policy and strategy

Current UK Government policy and strategy is leading public service organisations through a significant period of change to achieve efficiency gains through streamlined citizen-centric, ICT-enabled, secure shared services.

Understanding current UK Government policy and strategy will assist you in:

Understanding measures you should take to deliver ICT enabled business change

Identifying expected business benefits

Identifying costs

Identifying scope of change

Identifying risks.

A list of the key sources of UK Government policy and strategy can be found in the thought leadership section of the VEGA website.

Point 2 - Ensure board level buy-in and understanding

A board level information assurance champion should be appointed to act as Senior Information Risk Owner (SIRO) for your organisation. This recommendation meets mandatory requirement 3 from the HMG Security Policy Framework (SPF) V1.0.

Your SIRO should agree to terms of reference which clearly define their role and responsibilities with regard to the information assurance of your organisation. Additionally, your SIRO should meet regularly with your organisation's security staff to discuss security policy and discuss a risk managed approach to information assurance. This ensures that information assurance and governance is a recognised board level responsibility which includes the protection and utilisation of all of your organisation's assets (information, personnel and physical).

Point 3 - Manage your stakeholders

Obtaining stakeholder buy-in to your organisation's information assurance strategy is critical to its success. Good stakeholder management creates awareness, provides the framework for supporting delivery and assists you secure budget where resource is scarce and competition is fierce.

A communications plan should therefore be developed to identify:

Desired buy-in outcomes

Audience of stakeholders (internal and external)

How to best engage stakeholders

How messages are to be communicated

Ownership of responsibility for maintaining communications

Frequency of communications.

Stakeholders should subsequently be plotted on a stakeholder map prioritised by power and interest. This will assist you in grouping them. Your communications strategy can then focus on key stakeholders whilst ensuring other stakeholders are engaged to the level required.

Failure to gain buy-in from key stakeholders has sealed the fate of many information assurance projects.

Point 4 - Involve the experts

When pursuing an information assurance strategy, you should seek advice from recognised Government and industry experts. These organisations have faced the same challenges as you and have valuable information and knowledge to share. This will save you time and money, whilst ensuring that the information assurance solutions you plan to implement are fit for purpose and proven across Government.

The organisations you may wish to contact include:

Office Government and Commerce Buying Solutions (OGCBS)

Communications-Electronics Security Group (CESG)

Government Computer Emergency Response Team (GOVCERT)

Central Sponsor for Information Assurance (CSIA)

Centre for the Protection of National Infrastructure (CPNI)

Warning, Advice and Reporting Point (WARP)

Information Commissioners Office (ICO)

Public sector organisations similar to your own

Consultancies with expertise in enabling Transformational Government change programmes

Point 5 - Achieving and evidencing compliance

Recent data losses across Government have placed an increased focus on information assurance. Public sector organisations must comply with centrally released security policy (e.g. HMG SPF) which defines mandatory minimum security measures.

To connect to a secure network, your organisation must comply with mandatory security controls. Depending on the security impact level of the secure network, your organisation will either have to complete a Code of Connection (CoCo) or produce a Risk Management and Accreditation Document Set (RMADS).

To answer the requirements of a CoCo you should treat each control like an exam question (answer the question with relevant evidence), and sell your strengths, if you comply with standards such as ISO/IEC27001:2005 or PCI DSS.

The completion of a RMADS is much more involved. Unless your organisation has significant experience, you should involve a CESG Listed Advisor from the CESG Listed Advisor Scheme (CLAS).

Connection to a secure network will only be permitted once the relevant governing security authority is content that your organisation meets the information assurance requirements of the network you wish to connect to. This ensures that the risk your organisation poses to other organisations on the network is managed.

Once your organisation's connection is authorised, you should expect regular audits which ensure the level of information assurance your organisation has achieved is maintained and improved.

These five points will hopefully act as an aide memoir� when your organisation starts to consider its connection to a secure government network. The most important thing to understand is that information security is not just about technology; it is the catalyst for organisational change that encompasses people, training, policy and procedures.

VEGA is a member of the CESG Listed Advisor Scheme (CLAS), as well as a registered CHECK service provider. VEGA has an established track record of working across Government providing strategic advice and technological expertise to help secure public sector information through the implementation and use of secure Government networks.




By Damian Schogger, Communications Manager, VEGA

About VEGA VEGA is a professional services company that delivers technology-enabled change in complex environments, often where security and resilience are key. We have an in-depth knowledge and experience to support organisaitions planning to gain connnection to secure government networks, gained from working on several major UK government projects in this area.

Please contact us for further information. Connecting to Secure Government Networks

VEGA




Small Business - Compliance Isn't an Option Any More


Small Business Under Attack

Every day criminals attack businesses. Whether you own or manage a small or mid-sized businesses, or a non-profit organization you are a prime target for crime especially identity theft. Smaller businesses don't have the resources to properly protect proprietary information so the shift to smaller businesses is occurring at a faster rate.

Here are the facts from a survey by the National Cyber Security Alliance:

� Only 28% of small businesses have formal Internet security policies

� Just 35% of small businesses provide any training to employees about Internet safety and security

� 86% of businesses have no single individual focused on IT issues.

As a result:

� 85% of payment card breaches occur at smaller businesses

� 81% of organizations subject to PCI standards have not been found compliant prior to the breach

� 83% of attacks were not highly difficult to perform

The shape of Internet crime is moving from more tradition forms of crime including Phishing or randomly collected passwords and login information to targeted attacks where cybercriminals are stealing and reselling data to other criminals.

Experts are predicting attacks on small and mid-sized businesses will grow in 2010. These attacks will grow in sophistication and complexity. Unfortunately, most small and mid-sized businesses aren't prepared for this kind of attack.

It is important for businesses of all sizes properly protect their customers and employees private information. It is important for two reasons:

1. To guard against customer and employee identity theft and other crimes

2. Avoid fines for not achieving minimum federal, state and PCI standards

Customer Protection Isn't An Option Any More

Our government and private industry have noticed this trend of increasing attacks on small and mid-sized businesses. They realized the only way to stop or at least slow this trend is to put the responsibility on the businesses. Over the last 10 years federal, state and industry have set up new rules and regulations to force businesses to secure customer and employee proprietary information or face huge fines or possibly jail time.

Businesses must take the steps to get compliant with the law and PCI standards. They must get serious about protecting their customer and employee proprietary information. Protecting this important information isn't an option for any size business any more.

Who must comply?

Here's a general rule: If your business collects, uses, transmits, or stores personal financial information about your customers, members or employees, you must comply with laws and regulations including PCI standards and the upcoming Red Flag compliance. Full compliance with the federal, state and PCI standards will prevent penalties, fines and security breaches. It will increase customer confidence and sells.

Meeting these tough regulations and standards is not easy to achieve, but it is rewarding. Many compliant businesses report full compliance has actually saved them time and money.

Smaller businesses don't know how they are going to meet these tough federal, state regulations and PCI standards. So, they are looking for assistance. There are many companies who offer assistance. Make sure you work with a company that has the experience and expertise while at the same time makes it quick and easy to meet the minimum recommended technical and administrative safeguards required for compliance with information security and privacy standards. The company should offer:

� Technical Safeguards

� Administrative Safeguards

� Security Breach Response

The right company should assist your business to meet all compliance standards and requirements. The company should work side by side to develop comprehensive technical and administrative safeguards required for your business to keep hackers and identity thieves out.

Your compliance to PCI standards and all other regulations will mean increased sales by increasing trust and loyalty with your customers. It will eliminate down time without you or your staff being sidelined by computer problems.

Most important, a good quality compliance company should walk you through all compliance requirements and assist in making sure you understand what need to be done to ensure they are met with a single, affordable program. This is a simple way for your business to meet or exceed federal, state and PCI standards and requirements for protecting your customer's and employees personal information against identity theft and fraud. It also shows your commitment to doing business the right way, with a genuine commitment to privacy, safety and trust.

In 2010, Smart business owners will work toward becoming compliant certified to save time, money and avoid those huge penalty and fines.




Warren Franklin has worked in the Internet security and identity theft protection arena for five years. He is regarded as on of the top security specialists in his company. You can contact him about business compliance and other computer security issues by e-mailing divpro123@comcast.net. More information on federal, state and PCI standards is available at http://www.completeinternetprotection.com/pcistandards.html




 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Information Computer and Technology - All Rights Reserved
Template Modify by Creating Website
Proudly powered by Blogger