Every day in the digital economy there are new
technologies, new vulnerabilities, new threats and new
issues. Traditional isolated information security programs
are no longer able to effectively address these challenges.
An integrated and continuous approach to information
assurance is the most efficient means of achieving an
effective information assurance posture that improves
accomplishment of mission or business goals.
The first step to information assurance starts with the
acknowledgment that information assurance is a vital
component of everyday business and deserves management
attention and financial support. The current best practice to
start this process is the establishment of an executive level
steering committed of the business, operational, security
and other departments critical to achieving the goals of the
organization.
This group then takes the leading role in the selection of
standards, assessment of current posture, identification of
risk management issues and the selection of solutions. By
applying proven expertise and “best practice”
methodologies, information assurance professionals
identify the critical information assets of an organization
and then tailor the policy, programs, procedures, and
solutions to continually protect those assets. An
information assurance solution should improve an
organization’s IA posture without hindering (and even
potentially improving) its accomplishment of mission or
business activity. A strategic partnership should be
established between the business, operational, and security
functions of the organization to effectively implement
information assurance.
The competitive advantages of improved processes,
reduced losses, improved customer confidence, enhanced
employee productivity, and increased goal accomplishment
are awaiting those organizations and companies that
implement a professionally engineered information
assurance program.
Organizations that are working or have implemented robust
information assurance programs should then look at their
sector of society. Whether it is government, education,
commercial or non-profit, achieving a robust and secure
international digital economy, offering a safe, private
environment for governments, businesses and individuals
should also be a goal. It starts the same way the Internet
itself started thirty years ago, with peoples of common
interest coming together, talking openly, identifying
common issues, discussing solutions, establishing standards
and sharing best practices.
The leadership for information assurance in the growing
digital economy designed with the intent of permitting the
safe exchange of information, goods and services on a level
playing field, must spring from the senior levels of industry,
government and society. Business leaders should establish
the foundation through discussion of commons issues,
problems and solutions to define and defeat computer
crimes and work with vendors to incorporate security into
upcoming products. The goal is to increase coordination to
make a safe digital economy a reality and also making
computer crime and abuse a higher risk, lower return
venture for criminals and unethical individuals, groups
businesses or governments.