Kenya works on training information security managers
Notes from all over
- Clues point to Jan. 13 release of Windows 7 beta
- Microsoft releases Vista SP2 beta
- Obama's DHS pick may find support for raising H-1B cap at confirmation hearing
- IBM wants info from Apple execs in Papermaster case
- License server glitch exposes SonicWall users to e-mail security threats
- Report: Former AOL chief exec tries to raise funds to buy Yahoo
April 28, 2008 (IDG News Service) A lack of training institutions for information security management has made IT investment expensive for many organizations in Kenya.
Companies have invested in training IT managers abroad, which is expensive for small and medium-size businesses in Africa, said James Gathage, a consultant at QualityPlus, a Kenyan training company for information security management professionals.
This has led some companies to neglect information security and management as integral parts of business and organizational growth, he said. So, to reduce costs and make courses affordable, training companies are bringing experts in to train local IT managers.
The reduced cost is expected to encourage government offices as well as corporate entities to start addressing the issue of information security management.
"Today's professionals have learned to travel light, keeping only what's necessary. [Criminals] do not need to steal the whole computer to destroy the company," Gathage said. "A simple flash disk can be used to steal sensitive data from the office."
Gathage sees this security challenge as the main reason government offices have resisted full computerization and digitization of all services.
According to Gathage, government offices have huge cabinets where they file tax records and payroll information -- records that are now being transferred to computers. In a corporate setting, the computer system is likely to have financial data from suppliers and credit-card numbers from customers.
"In the hands of an identity thief, this information is a tool for draining bank accounts, opening bogus lines of credit and going on the shopping spree of a lifetime -- at the expense of your company, your employees and the customers who trust you," Gathage said.
To safeguard client information and protect themselves from corporate espionage, companies are forced to adopt information security management systems (ISMS).
The key concept of ISMS is for an organization to design, implement and maintain a coherent suite of processes and systems for effectively managing information security, thus ensuring the confidentiality, integrity and availability of information assets and minimizing information security risks.
An ISMS makes business sense, because customers want to do business with entities that will not expose their personal information and businesses want to seal all loopholes that may expose them to risks.
Gathage noted that an ISMS, as with all management processes, must remain effective and efficient in the long term, adapting to changes in the internal organization and external environment. An effective ISMS guarantees that the internal and external loopholes are sealed.
"For example, most hospitals in Kenya are keeping their records in electronic form. How are patients assured that their records are well protected and will not land in the hands of their enemies or people who may expose them?" Gathage said.
Reprinted with permission from
Story copyright 2008 International Data Group. All rights reserved.
Today's Top Stories
Resource Alerts
Webcasts
Advances in SSL and Certificate Management
Real-time collaboration and development with IBM® Rational® Team Concert streamlines any project
Editor's Picks
Clues point to Jan. 13 release of Windows 7 beta
Microsoft releases Vista SP2 beta
Obama's DHS pick may find support for raising H-1B cap at confirmation hearing
IBM wants info from Apple execs in Papermaster case
License server glitch exposes SonicWall users to e-mail security threats
Report: Former AOL chief exec tries to raise funds to buy Yahoo
Record Capacity for Microsoft® Exchange 2007 With VMware and IBM System x3850 M2 The more e-mail becomes an entrenched IT infrastructure application; the more messaging administrators face numerous demands. Employing a virtual solution can help avoid expensive over-provisioning of server computing resources, while improving management and disaster recovery. This whitepaper explains how to break down the scalability barrier and respond faster to your mail system needs.Download this white paper now!
|
| White Papers Read up on the latest ideas and technologies from companies that sell hardware, software and services. | ||||||
|




Subscribe to
Computerworld 


Read up on the latest ideas and technologies from companies that sell hardware, software and services.