Kenya works on training information security managers
Kenya works on training information security managers
Rebecca Wanjiku
April 28, 2008 (IDG News Service) A lack of training institutions for information security management has made IT investment expensive for many organizations in Kenya.
Companies have invested in training IT managers abroad, which is expensive for small and medium-size businesses in Africa, said James Gathage, a consultant at QualityPlus, a Kenyan training company for information security management professionals.
This has led some companies to neglect information security and management as integral parts of business and organizational growth, he said. So, to reduce costs and make courses affordable, training companies are bringing experts in to train local IT managers.
The reduced cost is expected to encourage government offices as well as corporate entities to start addressing the issue of information security management.
“Today’s professionals have learned to travel light, keeping only what’s necessary. [Criminals] do not need to steal the whole computer to destroy the company,” Gathage said. “A simple flash disk can be used to steal sensitive data from the office.”
Gathage sees this security challenge as the main reason government offices have resisted full computerization and digitization of all services.
According to Gathage, government offices have huge cabinets where they file tax records and payroll information — records that are now being transferred to computers. In a corporate setting, the computer system is likely to have financial data from suppliers and credit-card numbers from customers.
“In the hands of an identity thief, this information is a tool for draining bank accounts, opening bogus lines of credit and going on the shopping spree of a lifetime — at the expense of your company, your employees and the customers who trust you,” Gathage said.
To safeguard client information and protect themselves from corporate espionage, companies are forced to adopt information security management systems (ISMS).
The key concept of ISMS is for an organization to design, implement and maintain a coherent suite of processes and systems for effectively managing information security, thus ensuring the confidentiality, integrity and availability of information assets and minimizing information security risks.
An ISMS makes business sense, because customers want to do business with entities that will not expose their personal information and businesses want to seal all loopholes that may expose them to risks.
Gathage noted that an ISMS, as with all management processes, must remain effective and efficient in the long term, adapting to changes in the internal organization and external environment. An effective ISMS guarantees that the internal and external loopholes are sealed.
“For example, most hospitals in Kenya are keeping their records in electronic form. How are patients assured that their records are well protected and will not land in the hands of their enemies or people who may expose them?” Gathage said.
The training, offered at QualityPlus offices in Nairobi, helps large corporate organizations develop information security policies and adopt a standard that will make it easier for other international companies to identify with.
After training, the information security manager must establish and maintain a security program that ensures three things: the confidentiality, integrity and availability of the company’s information resources. Those have long been established as the core principles of information security.
The international standards body ISO has established a standard recommending that during a risk assessment, it should be established that a company has a security policy as well as strategies for asset management, human resources security, communications and operations management, information systems acquisition, information security incident management, and regulatory compliance.
Posted: April 30th, 2008 under Business News.
Comments: 7
Comments
Comment from Mohamed Mahat
Time: October 24, 2008, 11:36 pm
Hi,
Im an Information security and computer forensics masters holder,I am currently writing my thesis on information security and policy making in Kenya. I find it difficult to obtain information regarding this issues. Could you please give me ideas or pathways to follow that would yeild more information?
Best regards.
Mohamed Mahat
Comment from Andrew Byama
Time: December 10, 2008, 4:13 am
Where are the offices of QualityPlus in Nairobi and what are their contacts?
Comment from susan
Time: April 29, 2010, 3:42 am
hello,
which school would you recommend for a kenyan student like me to learn masters in information security……
Regards,
Comment from matunda
Time: May 6, 2010, 11:31 pm
There many good master programs that have emerged in recent times, especially in North America.
I liked the one I taught at University of Ontario Institute of Technology (www.uoit.ca) because of its mix balance between being academic and business.
George Washington also has an excellent program and because of its location of the school has excellent experience of people taking the program: government, military, business and the like.
University of Western Ontario, where I studied, has a good academic bent towards academic and research.
I also believe the University of Nairobi has a similar program for those that want to study in Kenya.
Comment from John Nguru
Time: March 21, 2011, 7:01 am
I like the insight brought about by this article, I think the reason why people or corporations are looking outside in terms of IT security training is because many are unaware of available trainers in Kenya. If you are interested in IT security Linques Communication Limited will be running a training program from April 4th 2011 to April 15th 2011. For more information contact Linques at training@linques.co.ke or visit our website http://www.linques.co.ke, you could also call us +254 711 689 938.
Comment from milton kioko
Time: May 6, 2011, 4:35 am
Hi Sir / Madam
I am Milton kioko from Kenya age of 38 yrs, kindly requesting for job / Children Support in education fees. Three children are at home for lack of school fees, while i have an experience but no job
I have Driving license & Valid Passport to travel worldwide where any assistance arises.
I have attached fees structure for children and see how you can help me, Including their photo.
Looking forward to hear from you .
Hoping God Will touch You For Any Assistance.
Thanks Milton kioko— Kenya.
Tel: +254721663986 / Wife Winnie Tel: +254714593207
Comment from PATRICK NKUNGA
Time: November 17, 2011, 7:10 am
I am a security officer and my request is kindly can you sent me some of training that you think are appropriate for me. In areas like security policy writing, asset protection, crime prevention and cotrol, work place safety etc. Thanks.
My mobile Number +254724618917
Write a comment