NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Program
Slice by Program

Frontiers of risk

By: Mark Els(12-12-2006)

It's a safe bet no organization anywhere can be 100 per cent secure. A constantly changing cyberscape helps guarantee this. It's also why security and IT managers can never run and hide from risk management and threat assessment.

Among the many elemental, technical details of the federal government's Management of IT Security (MITS) standard, one overriding theme has ruled them all: IT security is very much about making sure there's good awareness of business risk management.

A key aspect to MITS, since its inception in May 2004, has been to get all the government's business leaders on board. Assistant deputy ministers and deputy ministers have to be well aware of the risks around their program delivery and then translate that risk management into their IT security posture.

"MITS is founded fully on a risk management approach," says Jim Alexander, the federal government's deputy CIO. "It's about dealing with this as a business risk management piece, as opposed to some technical thing and, 'You better make sure nothing ever goes wrong.'"

More than 100 federal core public service departments and agencies are subject to MITS and every one is expected to comply with the standard by the end of next month.

But if senior management engagement and identifying the real business risk management presented challenges, the sheer volume of work towards compliance - and exactly what form that compliance would take - has proved daunting.

MITS is viewed by and large as a high-level document, at least as far as standards are concerned. It attempts to define the baseline requirements to achieve a minimum level of security, but details on how to actually implement some of the items are few and far between.

"As far as using MITS to help guide us to achieving security, it really is more of just a guideline than a standard for us," says Paul van Gurp, IT security manager at the Office of the Superintendent of Financial Institutions (OSFI).

"I guess the grey area is what exactly MITS compliance means, and how do you know when you're MITS-compliant?" he says. Resources for implementing MITS are also scarce, despite assistance from Treasury Board Secretariat, further guidelines from the RCMP and Communications Security Establishment (CSE), as well as proactive collaboration between departments and agencies.

Exactly how far departments implement MITS will be an internal decision for senior management, says Van Gurp, who describes full compliance as a high and lofty goal.

"Not all departments and agencies have the resources or the time to be able to do things like certification and accreditation of all their systems, and threat assessment and risk management.

"It's one roadblock in MITS compliance for a lot of departments and agencies, including ours."

To find and understand risks, Van Gurp says most government departments and agencies, as well as third-party vendors, look to the CSE and RCMP for standard methodologies of assessment and for recommendations to mitigate risk.

"Risk management typically means identifying your assets, the value and criticality of those assets, what the threat agents are and the likelihood of that threat agent affecting your organization's assets," he says.

"It's the vulnerability and the likelihood that vulnerability will be exploited and the risk associated with all those factors."

Alexander concedes MITS is a very detailed IT security standard comprising many elements, and there is no doubt about the scale of work involved in threat and risk assessments and certification.

"Across most of our programs, we are very dependent on some sort of IT support. And that does mean there's quite a volume of work to do. IT security is something we're taking very seriously as the Government of Canada, but so are a lot of other organizations, both public and private sector.

"And therefore there are scarce resources and there are often fairly urgent timeframes on some of them. In the end, it's just sort of a risk management, and therefore there still are incidents to respond to, and to respond to effectively."

The key thing, he stresses, is that MITS is a standard and Treasury Board expects departments and agencies to comply with it. "To keep compliant and to make sure we maintain the security posture we need, there's going to be ongoing activity needed."

As regulators of Canada's financial institutions, and given some of the highly sensitive data that's housed there, the OSFI is definitely among the more hard-pressed to adopt a tight security stance.

"Our standards are significantly higher than the requirements of MITS," says Peter Pearson, an IT security infrastructure specialist at the OSFI. "And the sense I'm getting from peers at other agencies also is they're not comfortable applying just the minimum."

"With MITS compliance, it almost sounds like you have a start line and a finish line, and in December everyone can take a breather and just stop doing security, but obviously that's not the case," adds Van Gurp. "We're always thinking of security. MITS outlines those base requirements, but we won't stop considering ways to improve our security."

For Internet security and the inspection of malicious code, the OSFI has been using appliances from Finjan Inc. since as far back as 2002. More recently, the agency has implemented a two-factor PKI authentication process and implemented full disk encryption on all workstations and laptops.

"There are a lot of different pieces we've put into place in advance of the deadline, but there's always some uncertainty," says Van Gurp. "It just depends on finding the right time, the right resources and having the internal discussions and agreements in place to make those things happen."

Departments and agencies are individually accountable for the integrity of their program delivery, and therefore the IT security that's underneath that, Alexander notes. Government units have twice had to undergo a self-assessment process against all the elements of MITS, in September 2005 and again 12 months later, and report back to Treasury Board on their progress and plans for compliance with MITS.

"It's clear we need to address IT security in a very proactive way," Alexander reiterates. "MITS is a very effective foundation, but we realized we wanted to move beyond just that, to develop an IT security strategy which addressed a number of other key aspects.

"As required, we'll continue to refresh these standards to address emerging risks and trends."

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada