Alessandro Moretti
Teamwork is key

Teamwork is the key to success

IT and legal teams must work together to ensure effective risk management of growing amounts of information

Written by Alessandro Moretti

The biggest challenge in risk management is that many global organisations are growing rapidly and information is becoming more available.

Businesses want information faster and to quickly fire it off around the globe. They want to send it to their trading partners, and they also want to receive data from those partners or other stakeholders.

So information is growing in volume and is being distributed around the
organisation at a very fast rate. There has been an exponential increase over the past 10 years and now most organisations ­ and even people at home ­ have huge amounts of stored electronic data. In terms of volume and accessibility, it is getting quite complex.

Clearly, IT departments need to work very closely with legal teams, so that they understand the data that is in use in the organisation.

Legal experts have to set policies that can be interpreted by IT people so that controls and standards to manage that data can be implemented.

There has to be a good working relationship between the two disciplines, and this cannot be stressed enough. It is, of course, two-way, so legal teams have to understand the policy and the data in use in the organisation.

From an IT standpoint, it is important to communicate back to legal and explain the types of data that are in use, and the processes that data is being used for. IT controls need to be checked to ensure they are operating effectively, and legal teams need to be confident that the policy is being enforced.

IT should lead on the technical component of electronic discovery, to address where and in what systems the data can be found and to recover the information. Other IT or business professionals may well analyse the data.

However, from an incident and investigation perspective, direction needs to come from the legal team, because it is that team which will give the exact parameters of what discovery is needed.

Standards such as BS17799 which cover information security management are the core principles of managing information within an organisation. One of the things to which an organisation should pay attention is a confidentiality policy, so that how to label data and apply the appropriate security controls is clearly
understood.

A classification policy about data is absolutely fundamental and, from there on, an information security management system, IT controls and procedures can be implemented. And it is important not to forget the importance of testing.

Alessandro Moretti is a risk management expert from UBS Investment Bank, and sits on the European advisory board of IT security certification body ISC2.

This article is based on a transcript of Moretti speaking at the Computing web seminar “Do you know where your data is? How IT and legal teams can work together on data protection implications.”
www.computing.co.uk/webseminars

Tags:

reader comments

related articles

 

Infosecurity teams still isolated

New research from Ernst & Young finds many security teams are still struggling to integrate with the business 10 Dec 2007

NHS must learn lessons on centralised patient records

Programme so far has not focused enough on social aspects of the technology change 06 May 2008

NHS must learn lessons on centralised patient records

Programme so far has not focused enough on social aspects of the technology change 06 May 2008

related whitepapers

today's top stories

Coding moves with the times

We examine how software development has evolved to better serve the changing needs of business, and speaks to IT leaders who are delivering significant benefits to their organisations by using the latest programming methods 15 Oct 2008

Agile framework simplifies offshore development

Case study: Getronics business application services 15 Oct 2008

Computing launches all-new IT jobs site

Updated Computingcareers.co.uk provides enhanced feature for jobseekers 14 Oct 2008

Q&A: BT Business head of SaaS, Chris Lindsay

BT's head of software-as-a-service explains the benefits of the on-demand delivery model and how the current economic downturn could force firms to re-evaluate how they buy software 14 Oct 2008

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

Features

Enter the dragons' den

Getting an innovative IT product off the ground takes cash, commitment and a lot of patience 15 Oct 2008

TimepieceFeatures

Coding moves with the times

We examine how software development has evolved to better serve the changing needs of business, and speaks to IT leaders who are delivering significant benefits to their organisations by using the latest programming methods 15 Oct 2008

Advertisement

Primary Navigation