Please wait while the page is being loaded Skip this advertisement >
Wednesday | 3 December, 2008
Execs debate IT security, governance in Sydney
Australia leads world in IT governance
Darren Pauli 08/09/2008 13:23:00

Enterprise executives have converged on Sydney to talk security and the future of IT governance.

The Computer Audit, Control and Security Conference (CACS) 2008 conference will bring together IT professionals from BDO Kendals, Brisbane City Council and the Commonwealth Bank to discuss the role of IT as a business enabler and the latest developments in IT security.

Howard Nicholson, vice president of professional services organisation and conference sponsor ISACA – formerly the Information Systems Audit and Control Association – said CIOs must understand IT governance to be successful.

“If IT is not contributing value to the business, it is destroying it. If your security leaks like a sieve, you'll lose customers and reputation,” Nicholson said.

“IT governance has only been formally recognised over the last three years. Professionals the field have managed governance across all industries that need to align IT with business strategies.

“You're in trouble if you can't sum up your business objectives in a sentence. Even though senior directors are more tech savvy now, they sometimes don't understand the real business objectives and therefore don't know the role of IT.”

Nicholson, a former audit manager for Centrelink and IT staffer for 23 years, said outsourcing is the biggest challenge to hit IT governance because it can be difficult to see where business data resides or who has access to it.

“Do you know where your data is? Senior executives often think they have a handle on IT but the outsourcers also outsource, so we need to make sure those accountable know the risks,” Nicholson said.

He said IT governance will be a critical part of the CIO role within five years will require a handle on IT governance in order to base decisions on business needs and the inherent risk of each project.

Knowing how to plan projects or when to can them is an invaluable skill in IT governance, Nicholson said, because it can improve or seriously damage business operations. He said some of the best examples of good governance is shown by managers who save potentially hundreds of millions by re-evaluating ailing projects, “even if stopping it costs of $20 or $30 million”.

Australia is set to lead the world in IT governance, Nicholson said, because locally produced standards and industry practice are simpler and better planned than international developments. He said Australian practices, such as the AUS4360 security standard which is vieing for ISO 3100 accreditation, have fewer mistakes and are built with better insight.

ISACA has created an IT governance certification program dubbed “Certified in the Governance of Enterprise IT” (CGEIT), that recruits professionals with eight years' experience in the field as mentors for CEOs, CIOs, and IT managers looking to understand how IT can better serve business operations. Nicholson said student and mentors, who include business executives, IT managers and consultants, should understand both IT and the business but need only an “extremely broad understanding of IT”.

ISACA's Howard Nicholson
ISACA's Howard Nicholson
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 
CA Knowledge Centre

Security Management

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our IT security solutions.

IT Security as a business enabler?
Download Whitepaper

CA Knowledge Centre

Success Stories


Australian Unity minimises costs and maximises productivity with single sign-on for 1,400 users
Australian Unity needed to address its business and security risks including user management and application security management. The company chose an enterprise single sign-on (ESSO) solution and discovered increased employee productivity, reduced help desk costs and elevated data protection.
Download the full Success Story


BT saves more than £15 million and improves customer services with comprehensive Identity & Access Management
To enable future growth and ensure its services remain competitive, BT needed to build closer relationships with its customers and suppliers. Discover how the company is now performing over 36 million transactions a day with their improved Identity & Access Management Solution.
Download the full Success Story


Identity & Access Management


Simplify and Secure: Managing User Identities Throughout their Lifecycles
Organisations are constantly challenged to keep pace with ongoing changes to users and their roles, responsibilities and requirements. Discover how CA can help you create a unified approach for managing users identities, providing them with timely and appropriate access to applications and information.
Download Whitepaper


Simplify, Integrate and Safeguard Your Business with Secure Web Business Enablement
Modern organisations are required to aggressively expand the number and type of Web applications and services provided to customers, partners and employees. Discover how to automate, delegate and centralise your key processes and services including user administration, access policies, auditing and compliance by reading on.
Download Whitepaper


Simplify, Integrate and Secure: Providing Secure Access to Server-based Information and Resources Across Platforms
Distributed servers are a powerful asset in any company’s infrastructure. Over time, most organisations have acquired a variety of different platforms and are relying on them to house an increased amount of critical applications, processes and data. Read on to discover how you can achieve a consistently higher level of server access security across multiple platforms including virtual hosts and guest operating systems.
Download Whitepaper

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links