Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
Kotak Group Arrests Information Risks With 'Aristi'
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Business
  • Biztech
  • Kotak Group Arrests Information Risks With 'Aristi'

Kotak Group Arrests Information Risks With 'Aristi'

FP Archives • February 2, 2017, 23:08:24 IST
Whatsapp Facebook Twitter

The Kotak Group is seriously thinking about information security and has taken steps to secure its group from a 360 degree perspective.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
On
Google
Prefer
Firstpost
Kotak Group Arrests Information Risks With 'Aristi'

Managing information explosion is a challenge for every enterprise and securing it is more of a concern. So, how can companies avoid massive security breaches, especially those who are involved in a host of businesses and have diverse requirements? Kotak Group has recently implemented a comprehensive risk management programme called ‘Aristi,’ to secure each company in the group.

In order to have a successful and apt risk management programme, the Kotak Group studied close to 4000 business processes across the group to identify loopholes and plug them for better risk management. Earlier, according to the company’s assessment, the risk management and information security was loosely handled.

STORY CONTINUES BELOW THIS AD

The Challenge

Ramesh Lakshminarayanan, Former Exe. VP and Group Head, IT & Infra - Kotak Mahindra Bank said, “As an organisation- risk management, information security and compliance was focused on more from a technology angle. While this was a good practice it was not enough to fulfil the holistic needs of the group. The final objective of ‘Aristi’ was to make business drive information security in the organisation.”

More from Biztech
Future Group - Reliance Retail Deal approved by CCI Future Group - Reliance Retail Deal approved by CCI RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market

For the project, Kotak Group wanted to garner business participation from all for inculcating information security as a part of their functional responsibilities; however the prevalent security posture was not up to the mark. The CIOs office wanted to convince the management for a comprehensive risk management programme, which was a compelling task. So, how did they get the buy-in?

A Novel Way of Getting the Buy-In

Mahindra Special Services Group (MSSG) helped do a quick dipstick test of the entire Kotak landscape (interestingly the MSSG was given complete freedom to visit Kotak Group’s building to look for loosely lying important documents, classified information written on pieces of paper, customer files with call centres, etc.). Post this exercise the group gauged the health of the organisation from a business security point of view. The results (filed with the management committee) of the dipstick test revealed that the group had a long way to go in managing information security.

The revelations were startling – it was found that data was copied in floppies, CDs (basically in external storage devices), files were freely available on cabinets and information was easily passed within the organisation and above all customer information was found available with tele-calling agencies.

Five Point Risk Management Programme – ‘Aristi’

STORY CONTINUES BELOW THIS AD

After realising the trouble that the group was in, a five point Risk Management Programme, ‘Aristi’ was decided to be instituted.

The first point on the agenda was to get a by-in from the senior management, followed by creating an educational programme and building channels for training. Thirdly, the group wanted to identify the information and security departments and identify loopholes in the processes. After identifying the processes, the fourth track was to put in the right controls to remediate the issues. Lastly, the group wanted to make the programme a part of the daily business operations. This programme was subject to tweaking as the situations demanded.

‘Aristi’– Putting it Into Practice

The implementation process required a human touch. The CIOs office along with the senior management; organised a team meet at an offsite location and conducted workshops that detailed on how information and security issues should be approached in the organisation.

The workshops were interactive and it gave cases and situational studies to the senior management, and they then came up with solutions for the same by putting the value of the asset to the incident and understanding the potential loss from them.

STORY CONTINUES BELOW THIS AD

After the workshop, the group focused more on knowledge and educating others across various levels in the organisation. They actually set up a demonstration in the office during tea and lunch breaks, which included a video of the MSSG exercise, the risk points and the controls to remediate the risks.

“The Business Information Security Officers (BISOs) and others from the information security team were provided small tools to strengthen the information security,” said Lakshminarayanan. These include encryption tools for email, entitlement tools to ascertain the right people are authorised to access files and the like. The importance of authorisation increases, given the fact that in spite of a secure file system configuration, loopholes do exist.

Kotak’s heterogeneity of line of businesses (LOBs) was a challenge. Every business has a distinct business process cycle and thus the treatment has to be in accordance as well. There is no one size all fits approach.

For example, the importance of research and M&A documents in an investment banking LOB is far higher than a retail LOB. “I am not saying it’s not important, but the kind of controls would be different,” said Lakshminarayanan. The respective LOB head has to be communicated accordingly.

STORY CONTINUES BELOW THIS AD

“LOB heads were taken into confidence while mapping the business process cycle, risk identification and remediation,” explained Lakshminarayanan.

Sustaining the Programme is The Real Challenge

“We had a thorough debate about this in our last audit committee meeting,” said Lakshminarayanan.

Audit is a key part of ‘Aristi’. The audit team is informed about the top ten risks of all the LOBs and they the scan through these risks during their regular audits.

“Secondly, to back the audit process we have a self-assessment programme in place too,” informed Lakshminarayanan. The LOBs certify themselves on a quarterly basis after following the procedures of the programme which is looped back again into the audit process.

With such an extensive project at hand, the Kotak Group is seriously thinking about information security and has taken steps to secure its group from a 360 degree perspective. This is especially important in today’s scenario where with data theft and fraud has become an everyday thing.

STORY CONTINUES BELOW THIS AD
Tags
Information security Kotak Group
End of Article
Written by FP Archives

see more

Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV