Government Technology
Public CIO Magazine: Technology news to public sector C-level executives

Risky Business

Feb 2, 2007, By Merrill Douglas

We've all heard about the analyst at the U.S. Department of Veterans Affairs who, in May 2006, took home a laptop that held personal information on millions of military veterans. When a burglar broke into his home then stole the laptop, the incident raised fears of identity theft on a catastrophic scale.

Luckily the laptop was recovered, and the FBI determined that the data had not been compromised. But the close call points out an undeniable fact: When something goes wrong with a government information system, the consequences can ripple far beyond the IT department.

Today, just about every aspect of government relies on IT. So when a hurricane destroys a data center, a hacker launches a denial-of-service attack, or the vendor of a key software application goes out of business, that doesn't just mean headaches for the CIO. It could also mean public-health professionals can't access patient records. Or teachers can't get their paychecks. Or police officers can't fight crime.

In other words, IT risk means risk to the entire government.

"People have to stop thinking of IT risks as independent," said Cal Braunstein, chairman, CEO and executive director of research at the Robert Frances Group, an IT consulting firm in Westport, Conn. "IT risks are a component of business and operational risk." IT risks comprise a growing range of concerns. Especially when it comes to data security, risk management has become a huge role. "Much more than we thought about four or five years ago," said Thomas Jarrett, CIO and secretary of Delaware's Department of Technology and Information. "And it's become a major focal point for the work we do."


Types of Risk
"In this day and age, privacy and security risks would be at the top of the food chain," said Patrick Pizzella, CIO and assistant secretary for administration and management at the U.S. Department of Labor. Thieves, hackers, spammers, virus launchers and others who try to steal data or sabotage systems constitute one of the major categories of IT risk. As government agencies open their systems to one another and to private-sector partners in the name of collaboration, and as they offer e-government services to the public, it becomes increasingly important to guard every door and window into the IT infrastructure.

IT plays a role in managing risk when it comes to physical doors and windows, as well as logical ones. In this post-9/11 world, concerns about physical security and information security meld, said Bradford Brown, managing director of the technology risk consulting practice, public services, at Protiviti Inc. in Vienna, Va. For one thing, that means CIOs must think especially hard about managing identity risk. "It's not so much even the physical protection of the building," Brown said, "but who's going to have access, how you're going to gain access not only to the building but to your network, what that access is going to look like, and how you are going to compartmentalize that."

CIOs must also be aware of risks outside of their managing sphere, such as the public telephone network and the power grid. "If you are an IT organization and are providing support for a 911 system, and power goes down and you have no way to get that system back up, it's not a reasonable thing to say, 'Out of my control,'" Braunstein said. "When the power does go out or other failures occur, you have to be able to address the problem, whether it is internal or external, and keep the mission-critical systems running."

Related Products and Services


Latest Government Technology News


Industry Solutions for Government

Read real world deployments of technology in government from our sponsors.

View All Industry Solutions

Marketplace


This section
brought to you by:
Ca - Transforming IT Management

IT Governance
Survey

Take this survey and get complimentary access to:

  • Gartner's: Magic Quadrant for IT Project and Portfolio Management, 2007
  • The Forrester Wave: Project Portfolio Management Tools, Q4 2007, Forrester, December 2007

The Power of IT Helps Oakland County, Michigan, Develop a High-Tech Future

  Yes! I would like more information about CA's solutions for Government.

IT Governance

CA Information Governance Solution Brief The CA Information Governance solution helps you solve an array of challenges with unique offerings including federated records management, email management, retention management and business process automation.

The Power of IT Helps Oakland County, Michigan, Develop a High-Tech Future CA helped Oakland County implement effective IT Governance and Service Management Solutions to support the evolution of their economy.

University Safeguards Wired & Wireless Access CA's Network ensures availability & performance of key systems with single, unified view.

CA Network & Voice Management Solution Brief Integrated, fault and performance management for end-to-end service assurance of multi-vendor, multi-technology converged networks.

IT Governance: Making the Difference in Cities, Counties and States Project and portfolio management helps government respond to old and new challenges. Featuring case studies from California Department of Agriculture, New York City, and Oakland County, Michigan.

Identity and Access Management

I Am Who I Say I Am: The Role of Identity and Access Management in Government. This whitepaper examines the role of Identity and Access Management in government using drivers such as the Real ID act and HSPD-12 as its guide.

Commonwealth of PA DPW Achieves Efficient Identity and Access Management with CA Identity Manager and eTrust® SiteMinder® The nearly 300 legacy applications at the Commonwealth of Pennsylvania -- Department of Public Welfare (DPW) were deployed as separate silos, each with its own user interface, access control list, security logic, business logic and IT support team

Project & Portfolio Management

Smart Enterprise Magazine Article: Bherwani Featuring Kamal Bherwani, CIO of New York City's Department of Health

Smart Enterprise Magazine Article: Cosgrove How Paul Cosgrave, New York City's CIO, helps keep the country's biggest city humming along.

Risk Compliance and Best Practices

The Changing Face of Network Management Automated NCCM tools reduce the downtime and degradation caused by configuration changes.

Business Service Management Links IT Services To Business Goals Adopting a process-centric approach to IT, applying ITIL® best practices and building a service-oriented team culture

IT Service Management Process Maps Select your route to ITIL© Best Practice

Deploying the CMDB for Change & Configuration Management The Configuration Management Database (CMDB) plays a critical role within the ITIL framework.