Managing data veracity and security practices vital to business

0
187

Clive Brindley | Senior Manager | Security Practice | Accenture Africa | mail me | 


In an accelerated digital landscape marked by ever-increasing amounts of data processed every day, information technology practitioners must navigate through multiple information lifecycle management practices daily to ensure the veracity of business data.

Simply put, data veracity speaks to the trustworthiness and truthfulness of data that builds on its confidentiality, integrity and availability, which form the cornerstones of most data security practices and are vital to business success.

Using trade secrets, intellectual property and other assets, organisations (including non-profit, governments, etc.) endeavour to bring differentiated offerings, product and capabilities to consumers, citizens and related stakeholders. These assets, in most cases, are digitised in various forms of technological constructs and need protection as with any physical asset.

A sound approach to data protection is therefore imperative. Business requires an approach based on four key pillars of data veracity and security practices to help ‘cut through the noise’ and enable practitioners and businesses to become brilliant at the basics.

Being ‘brilliant at the basics’ is a core principle that we promote in response to emerging studies which indicate that one of the top root causes of data breaches worldwide, is the fact that businesses fail at fundamental data security practices.

Information and data regulations

To understand data, requires that organisations first understand their business, which is not the responsibility of the information practitioners only, but of the entire business leadership.

In practise, this means that an organisation must be able to map out their entire business architecture (including the core business processes and flow); understand the role of data in each of these processes and pinpoint exactly where the data is stored and processed.

From there, sound knowledge of the external laws and regulations that govern the use of data must be acquired, and internal controls must be developed and implemented to ensure compliance, and ultimately build client trust.

To this end, regulatory statutes that must be taken into cognisance, could include: Going beyond just complying with general data protection through Protection of Personal Information Act (POPIA), the Payment Card Industry Data Security Standard (PCI DSS) and Sarbanes Oxley (SOX), to name but a few.

Apart from knowing the existing regulatory requirements, businesses must constantly remain abreast of any new developments and be ready to swiftly adapt to a constantly changing regulatory environment.

Information risk management

It is essential to identify the ‘crown jewels’ of the business early one, to determine how to best protect them.

By ‘crown jewels’ we mean those high-value assets that are most critical to the business operations and that are for example subject to the most stringent regulatory penalties or form the trade secrets of the business. Once they are identified, the relevant risk management policies and procedures must be developed.

However, it is important to note that this is only the first step in the risk management strategy. To effectively manage information risk, necessitates the adoption of a risk culture and mindset across the organisation, to ensure that information risks are identified and addressed, as and when they emerge.

This must be supported by business impact assessments to pre-empt the consequences of disruption of any business function and collate the information required to develop the relevant recovery strategies.

Ongoing monitoring and evaluation of the business performance in this regard is also critical. For example, we simulate cyber threats such as a phishing to determine whether all our staff follow the latest prescribed protocols, and if we score low, provide additional training and support.

Risk management is everyone’s responsibility and further supports the defence in depth paradigm.

Information and data governance

Businesses can no longer look at information and data governance as an ad hoc process, but must establish inhouse capability (people, processes and technology), supported by a formal framework to ensure compliance throughout the entire information lifecycle.

Organisations with a strong information and data governance culture are best positioned to respond to the fast paced and ever changing regulatory landscape.

Beyond the protection of information assets, the opportunity to exploit the vast amounts of data instantiated by the execution of business processes should not be squandered, provided due ethical, legal and compliance factors have been applied.

Information security frameworks and standards

Information security standards and frameworks are designed to improve the risk posture of organisations exploiting digital assets within their business.

There are many to choose from and often with much overlap. The good news is that much of the integration and standardisation across frameworks has been done by industry and governmental role players, it is this ‘20 per cent’ that needs you to focus on and tailor to your business.

Existing information security standards, frameworks and management systems can be leveraged, including the likes of:

  • The International Organisation for Standardisation (ISO) IEC 27001 specification;
  • The control objectives for information technologies (COBIT) framework of the Information Systems Audit and Control Association (ICASA);
  • The US National Institute of Standards and Technology (NIST) framework of standards, guidelines and best practices; and
  • The IT Infrastructure Library (ITIL) security management processes.

It is crucial to acknowledge that no data security measures are completely bulletproof, which is why the general perception has shifted from if an information breach will happen, to when an information breach will happen.

Businesses must therefore develop a solid incident response management system, procedures and protocol.

Information veracity in a nutshell

In summary, the four key pillars that underpin our proposed approach for establishing optimal information veracity are:

  1. information data and regulations
  2. information risk management
  3. information and data governance
  4. information security frameworks and standards

Broadly speaking, these four pillars collectively serve to ensure an understanding of the business, identify and focus on the crown jewels through a risk lens, formalise data and information governance, establish an integrated information security management system that is powered by the right technology and implement protocols for the ongoing testing of cyber security and privacy resilience.


 



LEAVE A REPLY

Please enter your comment!
Please enter your name here