Top security officials recommend accelerating investments in new technologies
RSA, the security division of EMC, has released a new report from the Security for Business Innovation Council (SBIC), which outlines three key areas where IT investments should be directed, as well as a series of recommendations on specific security technologies that help create a better preventive defense mechanism while improving business productivity.
According to the report, titled "Transforming Information Security: Focusing on Strategic Technologies," the three main areas where IT investments should be channeled are cyber threat resiliency, end-user experience, and cloud security.
The SBIC report leverages the knowledge and experience of security leaders from some of the world's leading enterprises, with the aim of helping other organizations dramatically upgrade their systems' protection capabilities and maximize the benefits of their investments in more complex IT infrastructures.
As part of their membership on the Council, SBIC members systematically monitor major technological innovations in IT security to ensure that they are not being developed or implemented in a hurry. Organizations now recognize that cyberattacks are inevitable and are focusing on how to minimize the impact of a potential attack.
Thus, security managers focus their attention on technologies and strategies that help them not only prevent a threat but also increase the resilience of systems against it, prioritizing investments that offer more detection and response capabilities.
In such an environment, the SBIC report confirms that Big Data analytics technology is a foundation for strengthening cyber threat defenses. Next-generation anti-malware technology is also among the key areas where organizations should invest.
The Council members highlight the importance of improving the end-user experience for a business’s productivity, and recommend investing in flexible authentication and identity management systems and methods to mitigate the associated risks. The report also evaluates cloud-based security services designed to help businesses gain greater visibility and control over threats.
The Council presented in detail three recommendations, which provide guidelines for the successful selection and deployment of new technologies, as well as maximizing investments in the field of IT security:
1. Look at least three years ahead
Using SWOT analysis, in conjunction with IT and Big Data strategy, and with the collaboration of internal audit managers, organizations can plan for the level of protection they need in an environment where threats and risks are completely dynamic.
2. Integrate different systems to get the big picture
If you invest in IT security today, the greatest benefit will come from the combined processing of information drawn from many different applications. The technologies available today make it easier to integrate data analytics, security intelligence, and GRC systems.
3. Maximize the value of investments through the implementation of standardized technological solutions
Leading security teams, well aware of the pitfalls of technological advancement, financial constraints, and potential frustration that can accompany the adoption of a new product, recommend a more formal approach to deployment, which helps to better manage the associated risk.
“Increasing the resilience of IT systems is at the core of an organization’s strategy to protect against cyber threats. Using the right technologies to gain greater visibility and analytics capabilities prepares organizations for potential attacks and helps them reduce their risk. The SBIC report provides the necessary guidance and helps security leaders make the right investments in relevant technologies,” said Amit Yoran, emeritus vice president at RSA, The Security Division of EMC.
"The speed of change is greater than ever. Every IT organization must integrate innovation and agility into its strategy. Because technology, after 18, or even 12 months, will have advanced, and because online 'enemies' will have adapted accordingly, be sure that there will be question marks regarding the reasons that obliged you to not follow the developments," noted Simon Strickland, general manager of security at AstraZeneca.
Source: newsbeast.gr


