Professionals task business owners on investment in security management

Security
By Chiazo Ogbolu
Lagos, June 12, 2018 (NAN) The Information Technology Systems and Security Professionals (ITSSP) on Tuesday called on business owners to invest in basic security management and control systems to secure their businesses.

The President of ITSSP, Prof. Adesina Sodiya, made the call at a media briefing in Lagos.

According to Sodiya, such an investment will help business owners to understand the nature of threats against their businesses.

He added that it would make business owners to understand the impact of a breach on production, finance, intellectual property and reputation.

The News Agency of Nigeria (NAN) reports that ITSSP is a cyber security advocacy group under the Nigeria Computer Society.

Its major goal is to promote and develop information security in Nigeria through stakeholders’ engagement, advocacy, capacity building, awareness, innovation and research.

Sodiya said: “Business owners are unwilling to invest in basic security management and control systems; they assume the Information Technology (IT) department should take care of any security issues that may arise.

“Organisations must continuously monitor their networks and have the ability to detect and mitigate intrusions as quickly as possible.

“Every organisation must develop information security policies, procedures and plans; these need to be updated regularly and enforced to help keep pace with the constantly-evolving threat landscape,” he said.

Sodiya said that human beings were often the weakest link.
“Consequently, an extremely high proportion of attacks involve social engineering approach,’’ he said.

According to him, in 2016, there were records that financial institutions in Nigeria faced Distributed Denial of Service Attacks (DDoS).

He said that it confirmed that online activities were not completely secure, adding that security awareness and training were therefore indispensable.

Sodiya advised that security should be established by balancing controls and risks to produce scalable and flexible strategies.

“Persistent internal monitoring and sharing of security intelligence are necessary for a more effective security approach.

“For a security strategy to be workable at present and for a long term, it is important to look ahead. Organisations tend to focus on reacting to security threats rather than being proactive.

“Functioning in this way provides no future growth in adoption of security framework. It is essential that organisations remain flexible and adaptable to achieve long-term security benefits.

“Organisations’ current security state, relative to the risk they are willing to take, and effective security alignment will determine the achievable desired security posture for the future.’’

He added that there was the need for proper implementation of the Cyber Security Act, 2015.

According to him, the implementation will go a long way in reviewing the state of information security in the country.

“There is need to address critical cyber security issues hindering smooth development of information security in Nigeria.

“To address such, proper implementation of the Cyber Security Act should be paramount,” he said.

The ITSSP president also called for inclusion of professional bodies in the Cyber Security Council.

Sodiya said that collaborative strategies and efficient practices would be required to achieve major security goals of Confidentiality, Integrity and Availability (CIA).

He added that cyber security protection required inter-professional expertise and collaboration from IT security experts, investigation officers, prosecuting officers, lawyers and judges.
“There should be strong collaboration with relevant government agencies in order to effectively curb the menace of cyber criminals in Nigeria.

“The collaboration should be with relevant stakeholders such as Central Bank of Nigeria, Nigeria Internet Registration Association and Nigeria Communications Commission.
“There is need for adequate and accurate cybercrime data in the country.

“The system for realising this should be developed and maintained by ITSSP,’’ he said.

Sodiya said that ITSSP would develop an intelligent incident handling system.

“Stakeholders should support the development of high level skill in IT,’’ he added. (NAN)
CAN/IGO
=========
Edited By Ijeoma Popoola