Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
Tackle Security At The Design Stage
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Business
  • Biztech
  • Tackle Security At The Design Stage

Tackle Security At The Design Stage

FP Archives • February 2, 2017, 23:07:30 IST
Whatsapp Facebook Twitter

Avinash Kadam, Director, COO & Head Delivery - MIEL e Security shares his views on varied issues related to Information Security.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
On
Google
Prefer
Firstpost
Tackle Security At The Design Stage

Avinash Kadam, Director, COO & Head Delivery - MIEL e Security shares with Biztech2.com his views on varied issues related to Information Security, ranging from the recently introduced DSCI framework to what should be the CISO’s strategy to convince management for information security projects.

What are your views on the recently introduced DSCI framework?

DSCI has proposed two frameworks - Data security and Data privacy framework. It is essentially an amalgamation of the best practices from various standards including 27001, to provide the appropriate level of security and privacy for the Indian organisations.

STORY CONTINUES BELOW THIS AD

The idea is that every organisation implementing this security and privacy framework will be able to assure the client that they are following the best practices in Information security and governance.

More from Biztech
Future Group - Reliance Retail Deal approved by CCI Future Group - Reliance Retail Deal approved by CCI RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market

Like any framework, this one too is well designed since it is based on so many matured frameworks.

The only concern is how DSCI will assure whether the implementation is really complete with all the required controls, checks and balances in place. The issue with all such frameworks is that they are in place just for the name sake to fulfill the regulatory requirements, but during an eventuality they would prove toothless.

Why is it critical that security should be thought of at the design stage itself?

Security cannot be an after thought, one that comes subsequent to an exploit unearthed by an ethical hacker, which is then adequately patched and then await the same hacker to identify the next potential exploit to be patched.

Security has to be built in at the design stage itself. It’s easy to define physical security, but cyber security has a number of vulnerable avenues like network security violation, operating system violation, application security violation, social engineering attacks, etc.

When the system is designed, the various potential attack types should be considered and accordingly each layer should be properly securitised. One should not wait for an ethical hacker to exploit it and show as vulnerability. These loopholes are already well known. So, if an application is compromised, it means that it was not properly tested with the necessary secure code review procedure. The problem should not be tackled from the wrong end. Security should be tested at the design stage and not after the product is delivered.

STORY CONTINUES BELOW THIS AD

What are the guidelines you suggest for patch management?

Firstly, companies should not apply a patch as soon as it is out. They should evaluate whether the patch is applicable, and then check whether that patch will impact any other processes. There may be a set of applications that can get vulnerable to the patch, compromising performance. Thus, patch management should not be fully automated.

Patch management is highly time consuming for the technical staff. Hence, patches should be selectively applied on a priority basis. Also, a team should be well designated to manage the released patches. We always talk about it theoretically, but every patch has to be tested in a regulated environment. And, only when it is tested out to be not impacting any other application that it is rolled out. This is not one of the technology chores. The team has to operate as defined and not when they get time, which is usually the case with most of the Indian organisations where patches are implemented once in a while, leaving a huge window of opportunity for people with malicious intentions.

STORY CONTINUES BELOW THIS AD

What should be the CISO’s strategy to convince the top management for security projects?

The CISO should gain the top management’s confidence because they are the driving force. The CISO is their eyes and ears as far as Information security in the organisation is concerned. The case should be put forward in the ‘business language’ that the board of directors understand. So, using the tech terminology will be ineffective and they will not pay much attention to this aspect.

The CISO has to make sure that all the identified risks are linked to the business case. He should be able to articulate scenarios that will unfold if the threats and security issues are not catered to, and what can be the possible ramifications.

So, the right use of the business glossary to the Board of Directors will make them understand why companies need such fat information security budgets.

STORY CONTINUES BELOW THIS AD
Tags
Hacking Security Information security Data Security CISO DSCI Patch Management security projects MIEL e Security
End of Article
Written by FP Archives

see more

Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV