To advertise, contact
Nathalie Akl
+971 4 2108520
nathalie.akl@itp.com
بالعربية
Where am I? Home /


BREAKING NEWS :

Adding up

By Sathya Mithra Ashok on Wednesday, February 06, 2008

Jeff Ogden, director of consulting at MENA for Symantec’s global services.

Jeff Ogden, director of consulting at MENA for Symantec’s global services.

Risk calculation is essential but to be successful it must be an ongoing process, not a periodic snapshot.

Risk calculation and mitigation is pretty much the first thing that enterprises need to do when they want to get an accurate idea of how much and where they should invest their security money.

"Business decision-makers always look to hard numbers whenever a budget is requested.

 

If risk management is to be successful it must be an ongoing process, not just a periodic snapshot.

They would like to see clear dollar values associated with the risk claimed to be out there, along with a clear RoI model linked directly to the business. Additionally, it is very difficult, nearly impossible, to be sure whether the investment put in place is really making sense to the business, or not, without realising the potential losses.

Therefore, calculating the risk becomes a necessity as part of the risk management process," says Ahmed Etman, security business development manager at Cisco Middle East.

Story continues below
advertisement



Guru Prasad, general manager for networking at FVC agrees: "Risk assessment is absolutely essential. IT managers have to do that to be able to justify to their senior management security spend.

Basically that is the way to tell the CEO that if you don't invest in technology, these are the risks that the business faces. They have to do that assessment before the top management can say ‘yes go ahead and spend that money.'

That is one of the things we have also seen that IT managers struiggle with - how to justify spending on IT and the answer is simple - just do risk assessment. It is like selling insurance; unless you are really told what could happen or something really happens to you, you never think about buying insurance.

The same concept applies when buying security products and solutions.

Apart from helping IT managers and higher management plan the security budget more accurately, risk assessment is essential for enterprises to understand the threats that are likely to visit them and acts as a reliable guide to fashion policies to prevent or subdue attack vectors.

In spite of the obvious necessity of risk assessment, many Middle East enterprises remain either ignorant of the concept or shy away from the prospect of using it to advantage.

"We cannot deny that the majority of enterprises in the region are still in their infancy when it comes to such disciplines in information security management practices; however, the progress is certainly obviously moving in the right direction.

Over the last few years, several organisations, mainly in the government sector, have been heavily focused on creating security and risk management frameworks," says Etman.

In the Middle East, probably less than 25% of enterprises do risk assessment.

A lot of them are working on standards such as ISO 27001 but I don't think they are necessarily connecting security to business functions. Of this 25%, I would say less than 10% understand the concept and think and manage the organisation from a risk perspective," states Jeff Ogden, director of consulting at MENA for Symantec's global services.

It is essential that Middle East enterprises not only understand the importance of conducting risk assessment but also put in place the right processes for getting the most out of the procedure.

Understanding risk

According to Symantec's recent white paper, many people confuse threats and vulnerabilities with risk.

To be at risk, an organisation needs to be subject to a threat that is able to exploit a vulnerability and then go on to cause an impact on some system or process that it is operating. All three elements: threat, vulnerability and impact need to be present for you to be at risk.




User Comments

All posts are sent to the administrator for review and are published only after approval. ITP.net reserves the right to remove any comment at any time for any reason. Please keep your responses appropriate and on topic.
Name *
( Remmber Me )
Email *
(Your email address will not be published)
City
Country
Subject *
Comment *
Security Code * Code
 


Please click post only once - your comment will not be published immediately.
Subscribe

Network Middle East English edition


The Middle East's leading monthly magazine for network professionals.

Subscription Rates:
FREE for GCC Countries, Egypt, Jordan & Lebanon *

AED 249.00 for International

Subscribe Now »

* Terms & Conditions Apply

Current Issue  |  Media Info  |  Subscribe to other Magazines »

Related Comment

Andrew Seymour
Concerns over skills shortages are being raised in the Middle East channel, with distributors and resellers desperate to get ... 

Related Feature

As good as new

Networks

While they have become well-established in more developed markets, refurbished systems, inspite of their obvious advantages,... 

Related Feature

Technology infects regional healthcare industry

Services

Hospitals everywhere are going high-tech. ACN looks at some of the technology trends currently shaping the medical... 


Competitions

Win Graphics Power

Ends On Thursday, 15 January 2009

Some of today’s top game titles have the ability to blur the lines between fiction and reality but that’s only if you have the right about of graphics horsepower sitting under your rig’s hood.


Advertising Features


Latest Products
Thermaltake V14 Pro

Hardware | Components | December 2008

Ready to take on water cooling kits.

RATING


Patriot SSD Warp 64GB

Hardware | Storage | December 2008

Ready for warp speed.

RATING


Gears of War 2

Games | Console | December 2008

Get ready for an overdose of action.

RATING


Sony VAIO VGN-Z12GN

Hardware | Notebooks | November 2008

Portable and powerful but can you live with it?

RATING


Technology Jobs
IT Support Senior Engineer
Location: Qatar, Qatar
Territory Sales Manager
Location: Dubai, UAE
Graphic Designer
Location: Dubai, UAE
Implementation Engineers
Location: Dubai, UAE

For editorial enquiries contact
Mark Sutton
mark.sutton
@itp.com
To advertise, contact
Ahmad Bashour
+971 4 210 8549
or ahmad.bashour
@itp.com


Arabian Computer News Channel Middle East Channel Middle East - Arabic Charged CommsMEA Network Middle East Windows Middle East Windows Middle East - Arabic ALL ITP TITLES