<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Changing Information Security Paradigm</title>
	<atom:link href="http://www.jasjit.net/2008/07/31/changing-information-security-paradigm/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jasjit.net/2008/07/31/changing-information-security-paradigm/</link>
	<description>Just another WordPress weblog</description>
	<pubDate>Fri, 30 Jul 2010 04:35:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Jasjit</title>
		<link>http://www.jasjit.net/2008/07/31/changing-information-security-paradigm/#comment-220</link>
		<dc:creator>Jasjit</dc:creator>
		<pubDate>Fri, 10 Jul 2009 08:42:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasjit.net/?p=23#comment-220</guid>
		<description>Thanks Suresh for reading blog and for your valuable comments.

Information security definitely needs to be a lot more context oriented rather than general framework oriented models that we have now.

I guess the key challenge is to understand the frameworks provided by organizations like ISACA, ITGI and aligning the information security services practices while taking care of business need, in the context of operating conditions.</description>
		<content:encoded><![CDATA[<p>Thanks Suresh for reading blog and for your valuable comments.</p>
<p>Information security definitely needs to be a lot more context oriented rather than general framework oriented models that we have now.</p>
<p>I guess the key challenge is to understand the frameworks provided by organizations like ISACA, ITGI and aligning the information security services practices while taking care of business need, in the context of operating conditions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Suresh Srinivasan</title>
		<link>http://www.jasjit.net/2008/07/31/changing-information-security-paradigm/#comment-219</link>
		<dc:creator>Suresh Srinivasan</dc:creator>
		<pubDate>Fri, 10 Jul 2009 06:29:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasjit.net/?p=23#comment-219</guid>
		<description>Hi Jasjit,

I agree to the fact that Information Security is often limited to the realm of IT/Technology controls. This is also due to the fact that the so-called Information Security consultants still address Information Security from an IT point of view and not from a business point of view.

There aren't many consultants who completely understands their client's business model before addressing their information security requirements.This eventually leads to a scenario where the same framework getting deployed at all client locations invariable of their business model.

Another reason for this is the fact that the ROI on IT controls could be demonstrated quite tangibly but there are very few professionals who are capable of demonstrating ROI on processes &#38; people hygiene to their clients.

When I say ROI, it has to be demonstrated from a business value point of view and not just in terms of metrices. I know professionals who blindly copy and paste some generic metrices to their clients without even understanding their releavance to their client's business.

Hence, there has to be a industry wide movement to change this outlook on Information Security and it has to be oriented towards practicality instead of blindly following frameworks provided by ISACA, ITGI etc.

Best Regards,

Suresh Srinivasan</description>
		<content:encoded><![CDATA[<p>Hi Jasjit,</p>
<p>I agree to the fact that Information Security is often limited to the realm of IT/Technology controls. This is also due to the fact that the so-called Information Security consultants still address Information Security from an IT point of view and not from a business point of view.</p>
<p>There aren&#8217;t many consultants who completely understands their client&#8217;s business model before addressing their information security requirements.This eventually leads to a scenario where the same framework getting deployed at all client locations invariable of their business model.</p>
<p>Another reason for this is the fact that the ROI on IT controls could be demonstrated quite tangibly but there are very few professionals who are capable of demonstrating ROI on processes &amp; people hygiene to their clients.</p>
<p>When I say ROI, it has to be demonstrated from a business value point of view and not just in terms of metrices. I know professionals who blindly copy and paste some generic metrices to their clients without even understanding their releavance to their client&#8217;s business.</p>
<p>Hence, there has to be a industry wide movement to change this outlook on Information Security and it has to be oriented towards practicality instead of blindly following frameworks provided by ISACA, ITGI etc.</p>
<p>Best Regards,</p>
<p>Suresh Srinivasan</p>
]]></content:encoded>
	</item>
</channel>
</rss>
