Skip to main content
Anniversary Image Gallery

Vijay Anand, CEO-VSD Infotech briefs on Information Technology

3 min read0 views
Sharefin

Vijay Anand, CEO of VSD Infotech is believed to be working towards strengthening India's position in Information Security Services and Infrastructure Management solutions through key strategic global initiatives. He has abstracted an article on the same. 

 
 

Technology has become an integral part of everyday business, though new technologies give unprecedented functionality it introduces new risks and environment harder to control. Increased dependency on technology means higher impact when things go wrong. A security breach will have a major impact. All are concerned about the privacy of their information and business losses and hence information security has become a part of technology Governance and corporate governance. Protecting and enhancing the value of our information and IT systems has become a central strategic objective in most businesses, second only to making profits. Information security is not just a simple matter of having usernames and passwords. 

 
 

Regulations and various privacy/data protection laws impose a raft of obligations on us. Information security controls improve the organization's profitability by reducing both the number and the extent of information security breaches, reducing both the direct and indirect costs (e.g. lost productivity through time lost investigating and resolving breaches and hoaxes; irrecoverable loss of data; expenses incurred in recovering and securing compromised data and systems; notification of customers and regulators; fines for breaching laws and regulations; damaged reputation leading to customer defections and brand devaluation).

 
 

Information Security Management System or simply ISMS, means a systematic approach to the organization's information security. With a proper Information Security Management System, adequate and appropriate security controls are implemented on the systems and networks that adequately protect information assets. This is also an easy way to ensure continual improvement of organizations information security by exploiting a process approach. The basic security requirements related to any organization, large, medium or small, are usually derived from three sources. First is the unique set of security risks to the assets of an organization's information systems. The second source of security requirements are those statutory and contractual requirements that an organization, its trading partners, contractors and service providers have to satisfy. Lastly, the third sources of security requirements are those principles, objectives and requirements for information security that an organization has developed to support its business operations. These could be derived from corporate directives and /or international best practices on Information Security Management such as British Standard ISO 27001 or International Standard ISO 17799. To establish the management framework for Information Security Management System, here is a recommended route. First one needs to define the scope of the Information Security Management System. An Information Security Management System can cover all or part of an organization.

 
 

Next one needs to also define and document Security/ Information Security Management System Policy. Also plan and carry out Risk assessment. One needs to develop Risk treatment plan. Select control objectives and controls with the help of ISO 27001 where a detailed list of candidate control objectives and controls are provided. One must also prepare a Statement of Applicability (SOA) where he needs to describe the control objectives and controls that are relevant and applicable to the organization's ISMS, based on the results and conclusions of Risk Assessment and risk treatment processes. 

 
 

Now obtain management approval of the proposed residual risks and authorization to implement and operate the Information Security Management System. To carry out Information Security Management System in the right way, you need to hire experts undergone some good information security course from some reputed institution and also a proper tool in place to manage and monitor your organizations information security.