As most of my followers (all 9 of you), may know our most recent subject in class dealt with organizational security. Protecting business from internal and external threats. Our two speakers represented the same organization from two different areas of IT security. Our first speaker was responsible for tackling issues related to Internet fraud, sensitive corporate information being shared, unintentionally or intentionally, and intellectual property issues. The other guest speaker from Legg Mason was charged with the IT infrastructure security - ensuring that IT property and corporate systems are well protected from intrusions, theft and other security issues. Both representing necessary roles within a firm to ensure that the customers, corporate IT systems and the company image are protected.
I found our first speakers role as extremely challenging and difficult for such a small team monitoring such a large spectrum (the World Wide Web) and tackling issues of fraud and blackmail while handling the various language barriers with a small team of virtual novices in a poorly defined role. Their ability to build relationships with the various local, federal and international law enforcement agencies to handle the relatively new frontier of Intellectual Property on the Internet is amazing. She describe how they have to use cleverly designed web crawlers that perform intensive web searches for certain key words that may signal an issue requiring her teams legal expertise to resolve. Additionally, her team seems poised to newly define the role of IT Intellectual Property - the team seems to find new ways to investigate possible leads .. they have no formal training or professional investigators but her team finds a way to discover who is infringing, stealing or blackmailing them while attempting to remain anonymous.. They don't just use the Internet either.. they make phone calls and perform investigative type activities to discover the criminals. Sounded really cool.
The second speaker spoke to us about the need bridge the gap between leadership and the employees and that the ability to understand the real meaning of corporate strategic direction and apply this to your projects and activities. Seems like it's always about bridging the divide between business and IT, right? He also reveled some valuable insight into how organization protect their IT resources, and why. He brought the issue of protecting corporate systems through encryption of virtually every facet of Legg Mason IT: files, external drives, hardware and intranets and corporate websites. He explained that that the security modus operandi of locking down all IT and then requiring employee justification for exceptions isn't based on malice but rather is the more sound approach to ensuring that no IT resource is left vulnerable due to an oversight. Examining each individual port request, website, media accessory and access to file system ensures that risks have been weighed and activity can be tracked. Tracking playing and important part in possible legal issues and allowing firms to accurately assess the extent of a security breach that may result in loss of data or exposure of client information.
Sunday, March 7, 2010
Subscribe to:
Post Comments (Atom)
Applying our Maximum Productivity DPO System
ReplyDeleteIT Infrastructure Security