Please wait while the page is being loaded Skip this advertisement >
Thursday | 20 November, 2008
ARN

ITIL takes on security management role

Implementing ITIL process improvements said to mitigate enterprise risk
Denise Dubie (Network World) 10 December, 2007 07:26:18

Long touted for streamlining processes and reducing operating costs, the ITIL best-practices framework also helps mitigate enterprise risk, say its adopters.

This week at the IDC IT Service Management and ITIL Forum in New York, analysts and enterprise ITIL adopters discussed how process improvements now are providing security benefits. A November survey of more than 300 companies by IDC revealed that security had surpassed improved availability and lowered costs as a main driver for adopting the best practices laid out in ITIL.

Specifically, some 56% of survey respondents indicated security as a motivation for ITIL, close to 50% said they wanted to lower costs and about 47% thought ITIL would help improve availability at their organizations. More than 45% said problem-solving was a driver for rolling out process improvements, and nearly 45% indicated that reducing errors was a top driver for ITIL adoption.

"Any type of process standard going forward will give you a chance to set policies and processes around security," said Fred Broussard, research manager of PC and device management software at IDC, during a presentation at the one-day event, which drew more than 100 attendees. "For instance, you can ensure only authorized users gain access and better guarantee unauthorized access doesn't happen."

The survey response might indicate a growing need among enterprise companies to better secure corporate data and information, considering processes around security information management have been incorporated into ITIL Version 3, which was released earlier this year. Dave Howard, national business technology manager for Toyota Financial Services (TFS) in California, explained to forum attendees how security policy creation and governance has been incorporated into the upgrade and how TFS has created a Security Center of Excellence and an Office of Privacy that align with some of the recommendations in the best practices framework.

"It is important to do security management," Howard said. He also explained how TFS incorporated security into his service design package process, in which models of a service are built and multiple criteria are taken into account. For instance, throughout the process of creating a service, his team has to determine the service's ROI, as well as which security requirements are necessary to deliver it. "For every new release we plan to push out into the environment, we also create a risk model," he said.

ITIL may not provide the external protections of a firewall, but it can go a long way in securing internal resources and preventing data breaches that have become commonplace among US companies.

"Security [can] be the motivation for doing some of these processes, such as patch and change management, for instance, because improving processes will make security work better in situations such as access controls," said Tim Grieser, program vice president of enterprise system management for IDC.

In addition, according to enterprise companies using ITIL, security and risk management could be an easier argument to make when trying to get executive buy-in for adopting ITIL. The ROI for process improvements can be ambiguous and not realized for quite some time, so putting an executive's mind at ease with talk of reduced risk may be the better way to go.

Being able to say "this change will result in a reduction of risk" will get management's attention, according to Oryst Kunka, vice president of process design and architecture at The Bank of New York Mellon in New York. "Sometimes it's hard to point out dollars with process improvements, but companies understand risk. At The Bank of New York, ITIL has become a business advantage," he said.

Related Stories
  • +

    Bill Gates: A New Approach to Capitalism in the 21st Century 28 January, 2008 07:12:19

    Transcript of Gates speech, and a Q&A at World Economic Forum in Davos, Switzerland
    As you all may know, in July I'll make a big career change. I'm not worried; I believe I'm still marketable. I'm a self-starter, I'm proficient in Microsoft Office. I guess that's it. Also I'm learning how to give money away.
  • +

    Three IT projects that matter 21 December, 2007 11:50:50

    Privacy, enterprise rights management and data-center automation projects are proving invaluable as companies look for new ways to protect data
    While rapid-fire cost-savings and consolidation efforts typically dominate an IT executive's annual to-do list, what's getting the green light this year are multiphase projects that protect organizations from regulatory fallout and data leakage.
ARN Directory | Distributors relevant to this article
Additional Resources
ARN Library
white paper Click here for case studies, whitepapers and other useful vendor content
Newsletter Subscription
Sign up for our ARN newsletters!
RSS Feeds
Market Place
 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
Play
Channel Watch
Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

How to Beef Up Your Sales Pipeline

Our economy may be heading towards a recession. Sales rates are dropping. Promotional campaigns are proving less effective than you would like. So how do you continue to grow your business and bring home the sales in such an environment? Download this white paper now to find the answers.

Sponsored Links