Overcomplicating Information Security and Risk Management

If I had to highlight a key problem area for organizations when it comes to how they approach Information Security and Risk Management overall, it would be the over-complication of their implementation(s), or lack thereof. (Sounds strange for the latter but it’s that “complication” that also results in the “lack thereof”).

Technology has done little to simplify Information Security for organizations when viewed away from a point solution perspective and judged from an overall enterprise perspective.

As new layers of technology are deployed to supposedly further enhance security, what we are seeing is not an increase in security but rather additional complexity and the whole security program becoming so complicated that few if any individuals have that holistic oversight about their organization’s actual security position. When you don’t have this definitive view, you have critical failure. This article; “The 7 Reasons Why Businesses are Insecure” looks deeper into how simple approaches, being neglected contribute to the overall failure of an Information Security program.

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Free Guide: Web Application Security
How to Minimize Prevalent Risk of Attacks

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Risks, Impacts, etc etc…..what do they mean in the whole scheme of things when they are rarely assessed outside of a specific system or application as discussed here? You’ve only got a fraction of the relevant data upon which to base a decision and/or strategy upon. The foundation principles of Risk Management have been forgotten! Yet, every major organization has a Risk Management group! What are they then doing for Information Security Risk Management? Ask them. I can guarantee you that they’re more than likely just doing project risk analysis, (and any Project Manager worth his salt can generally do that). Why? Because it’s all too complicated for them.

The foundation principles of Information Security and Risk Management haven’t really changed in the last 20 or more years but we seem to move further and further away from the basics – trusting in each new generation of the next big security software, appliance etc to deliver us some simplicity. Or, are we just hoping that it’s taking away accountability and the burden of us having to think and plan better? I’d say it is.

Related links:

Review of Information Security and Risk Management Practices – Complex or Staightfoward Exercise?
Workarounds, accepted mediocrity and questionable future benefits
Risk Management – Great in meetings, not so much in practice

I welcome your thoughts and feedback.

Drazen Drazic

About Drazen Drazic

Drazen Drazic is the CEO of Securus Global. Securus Global is one of the leading Information Security consulting organizations in the Asia Pacific region - also servicing clients from around the globe. He is directly engaged as a strategic consultant by many organizations, across most industry sectors on matters to do with Information Security policy and strategy. In earlier times, he has headed up Information Security for a large global investment bank and Big 4 professional services firm, worked as a regional IT Director, and has spent many years promoting and talking about Information Security. He is also the chief writer on the IT Security Management site, Beast or Buddha.


3 Responses to Overcomplicating Information Security and Risk Management

  1. Anon September 22, 2009 at 2:11 pm #

    We have lost touch with reality and common sense. Well said. Now to send this and links through to my management who will discard them because the concepts are not complicated enough.

  2. Anon Girl September 22, 2009 at 3:36 pm #

    My Philosophy

    The economic reality is the more systems we use, the more complicated the procedures we follow, the more equipment we have and the more information that we handle, the bigger the risk and the more it costs to maintain and protect.

    • If you don’t need to keep it – Don’t.
    • If it can be done just as well simpler – Do it.
    • If it has been replaced –Get rid of it.
    • If you don’t need to use it – Move it.

  3. Kristen Pike September 28, 2009 at 7:57 am #

    It’s amazing how many risk management solutions are founded in the concept of simplicity. When you look at the heart of any risk management planning, it’s all about proactively managing and simplifying what you can to decrease your risk.

Leave a Reply