Standard Chartered shores up defences

Bank aims for automated risk and monitoring control

Written by Emma Nash

Standard Chartered is updating its security systems to better defend itself against cyber threats and more easily resolve problems such as software patch management.

The bank, which has 500 offices in 55 countries, is introducing an automated risk management system across its global security operations, as well as managed security monitoring.

The company spends $11m (£6m) of its $400m (£217m) IT budget on security every year. It plans to combine the new technologies and procedures to create a sophisticated security infrastructure capable of providing automated alerts and processes using intelligent risk-based information.

'I believe we have an opportunity to apply automation to security and what I'm aiming for is automated risk and monitoring control,' said John Meakin, group head of information security at Standard Chartered.

'Like all banks we have a number of systems that go back a number of years. For the last two years we've said, to do risk analysis and to do it rigorously, you need to automate because otherwise the whole risk management becomes dependent on independent risk analysts,' he said.

Standard Chartered is using technology from specialist supplier Citicus One.

Meakin says the bank doesn't have the time or resources to build risk processes into applications at the development stage, and doesn't want to build its own system because of the maintenance costs.

'Obviously we are a business and the whole virtue of risk is we avoid spending too much money,' he said.

'We decide what specific security mechanism is required through risk. Once we have got this mechanism it becomes the security armament.'

In addition to the automated risk processes, the bank has signed a deal with NetSec for security monitoring.

NetSec will monitor and analyse information generated from firewalls and intrusion detection systems.

'They're taking large volume of data and boiling it down to a set of potential security events and then applying human judgement to see if these events require us to raise armies,' said Meakin.

'We always want more data and the best data because we want the best way of finding a new worm as quick as we possibly can, and we need to be able to analyse that as quickly as possible,' he said.

Meakin is keen to combine these technologies to provide a sophisticated security monitoring and alert infrastructure, as well as making tasks such as patch management significantly easier.

'As I look forward from 2004 to 2005 and 2006, what we want to do is take that risk method applied to getting the right security in place, take monitoring and then we want to link them together and detail specific issues where there really is no other magic solution,' he said.

'What I'm talking about here is patch management. Ideally we like the vendor to publish a fix, then apply them across your network. We have thousands of servers and tens of thousands of desktops across the world. It's a non-trivial problem getting a patch out to any number of servers particularly when you're racing against the clock.'

Meakin says monitoring techniques will be able to automatically locate a hole and close it. The intelligence of the system will allow vulnerabilities to be identified and severity analysed against the value of the servers or systems that need patching, allowing those that are most at risk to be dealt with first.

Tags:

reader comments

related articles

 

related whitepapers

today's top stories

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Open source bites back

Recession-hit companies are tired of vendors holding a gun to their heads over software licensing, says CEO of Ingres 09 Jul 2009

"We will ensure Britain remains at the forefront of the digital revolution"

As new trials of superfast broadband get under way, minister Pat McFadden explains the government’s digital vision 09 Jul 2009

Put social networks to work on your career

Increasing numbers of IT professionals using sites such as LinkedIn to grow contacts and find jobs 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation