| CIO stripped of duties |
| Posted by Moderator, CyberMedia India Online Ltd on
11/28/2008 |
Reply |
The World Bank it appears has stripped its CIO of his duties. (news clip: http://www.ciol.com/Enterprise/BFSI/News-Reports/Cyber-breach-Duties-stripped-from-WB-CIO/271108113136/0/ )
The media reports suggest that the bank's records which contain sensitive financial information from borrowing and donor countries were repeatedly and illicitly accessed over the last year. Director of Government Accountability Project (GAP) says the bank is looking for someone to take the fall for the breaches. Yet the entire episode raises several questions on the integrity of the CIOs. Is this really a black-mark on the CIO community? What can the CIO community as a whole do about it? |
| Re: CIO stripped of duties |
|
Replied by Sanjay Mittal, VIP Industries Limited
on 12/1/2008
| Reply to this message
|
World Bank is custodian of global trust, faith and money. Any breach of whatsoever is taken seriously. I think, it should be looked with overall perspective and not single out CIO role for that.
|
| Re: CIO stripped of duties |
|
Replied by RD Malav, Jindal Poly Films Ltd.
on 12/1/2008
| Reply to this message
|
In the era of information age, right information, at right time, to tight people is the need of the hour, which demands 24x7 availability of information to users, irrespective of geographical boundaries. Expectation from IT is to keep IT simple, in such scenario, security aspects are overlooked by IT people. Therefore It is imperative to have a separate person to look after security aspect independently like an audit dept looks after financial irregularities in books of accounts and reporting to board of directors.
I am of the opinion that a separate dept is to look after the security aspect similar to audit dept.
|
| Re: CIO stripped of duties |
|
Replied by Atul Bansal, Stewart & Mackertich Wealth Management Ltd
on 12/16/2008
| Reply to this message
|
| Generally banks are having separate Information Security officer who may or may not be reporting to CIO (generally reporting to CEO) to look after all information security risk analysis, audit & reporting. He is also responsible for deploying solution to check for any kind of sensitive information leak etc. So here CIO alone can not be held responsible for this breach in information security. Security policy maker, approver and implementers and Chief ISO should also be held responsible. |