WSTA Ticker - May/June 2008 - (Page 26) Continued from page 18 While best practices like these have been publicized, industry research reveals that U.S. enterprises are lagging in implementation of VoIP security measures—despite widespread proliferation of the technology. A 2008 survey conducted by In-Stat found that while 80 percent of respondents had deployed some type of VoIP solution in their company, more than 40 percent had no specific plans for securing their VoIP infrastructure. At the same time, most indicated their organization had a budget in place for network security. VoIP and IT audits Currently, examiners who conduct IT audits may or may not look at VoIP as part of their evaluations. Increasingly, however, VoIP will be a factor. The technology has already been incorporated into the FDIC’s standard IT Examination Officer’s Questionnaire. In conducting their work, IT examiners review the security mechanisms and controls financial institutions have in place to secure their computer systems during interactions between employees and customers. They seek to affirm the integrity, confidentiality and availability of the system, as well as compliance with federal laws and agency guidelines. As VoIP enters into the security equation more and more, examiners will begin to assess additional elements such as the nature of a VoIP deployment and the existence of any gaps in voice-data network topology that could be exploited. Remaining accountable Financial institutions are not the only enterprises that will need to prepare for this type of scrutiny. With the evolution of rules and regulations governing security and privacy of information—legislation such as the Sarbanes-Oxley Act, the Health Insurance Portability and Accountability Act (HIPAA), and the European Union’s electronic communications regulations— organizations in all sectors will need to devote greater attention to VoIP as an integral part of their network security plan. Rick Dalmazzi is President & CEO of VoIPshield Systems (www.voipshield.com), a leading provider of VoIP auditing and security products. He can be reached directly by phone at 613-224-4443 x201 or via email at rdalmazzi@voipshield.com. WSTA® Ticker - May/June 2008 26 http://www.soundcommunicationsgroup.com http://www.soundcommunicationsgroup.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.