As current events have shown, not taking security of digital systems can have drastic consequence
-
Recent Posts
Archives
Categories
As current events have shown, not taking security of digital systems can have drastic consequence
In the UK, there seems to be a cultural trend to stick to rules, boundaries and guidelines as if they are written in stone.
In truth this is not the true case for such things. Every day in the courts around the country, they argue, prove, counter argue the interpretation of the law and how it actually apply in the case that they are all involved. In other words, its flexible.
The same should be in the case of Project management and managerial tasks and activities. The bottom line in these en devours is not a fixed formula or program conducted by robots, it is performed by other human beings for human beings and human beings are not fixed static predictable organisms. Human beings ARE NOT ROBOTS!!!.
With this in mind, Project management is basically managing chaos. This means it must be flexible to the needs of the client and overall objective of the project and not the users or instigators of the proposed project.
There is a major difference between the original analysis, risk assessment and risk management and when the actual project goes live.
In a lot of cases unexpected or unconsidered objectives and incidents become the priority, but then Project managers try and force these factors to fit their original plan, rather than change their plan to fit the needs of the new criteria and client (s).
This then leads to projects failing to meet its targets, an overrun in costs, time constraints to appear and become unrealistic and a very low level quality.
The other factors is that this leads to stress, bullying, no compromises, conflict, increased costs, long hours and other negative effects on the workforce and client as a whole.
Therefore I suggest that you embrace the idea that things will change and therefore include and change your plans to fit rather than force them through, because then you will end up with a more successful outcome with additional income and a reputation of being a first class provider with a lot of return business.
BYOD or Bring Your Own Device, is one of the many popular trends in IT
The reason for this is many but the mains reasons in my opinion is as follows
the overall technical improvements made to mobile devices from being a phone and texting communication device to being a mini computer
running a modified Linux operation system running embedded HTML and Java scripts. this means they are true multimedia and programmable computers, but currently not true multitasking.
The overall cost effect of BYOD is making implementation a popular choice, the reason is that instead of a organisation, company etc paying for such devices, they have moved the costs onto their users/ employees who are very eager to take this one due to the convenience and time saving and just sheer enjoyment for such devices.
This freedom of movement means you are no longer chained to your desk or desktop device to access, use and complete your tasks. This can be done from anywhere you choose as long there is some sort of access point to connect to the internet
But this brings a whole host of problems for the INFOSEC professionals
As per usual, such schemes have not considered the security, as their intrinsic design is all about ease and freedom of access. A design trend that is dated to back in the early days of commercial computing around the 1970s on-wards
This is the heart of all the current problems associated with the security aspect IT
Therefore solutions are usually in the form of an afterthought or tokenism until a major breach occurs.
some of the main problems is not just the lack of proper security in these new devices, also cross contamination of data stored, theft of said devices, protection of sensitiveness data stored and tracking records of activity on them as well.
Most of the companies that produce these products have stored data of activity, location where these took place and what they actually did.
All of this info can be very useful to then plan a decisive attack on the main network servers/cloud that most companies have in place today.
The current thought is all around cost saving, but no real long term planning or effective risk assessment. Even though the real risk outlined can cost a company far more than they think they are saving.
Now add the ignorance of their employees of even basic INFOSEC procedures and we have disastrous situation just waiting to happen
Until the mindsets of decision makers truly take onboard proper security measures before something actually occurs then the worst these situations will get.
even though there is still no news on the unknown patient condition,