Riyadh-based network security firm IT Matrix has announced that its Operations Manager Mohsin Ejaz has completed training and certification as a BS7799 lead auditor. BS7799 is the most widely recognized security standard in the world. This standard is comprehensive in its coverage of security issues, containing a significant number of control requirements. Compliance with BS7799 standards is consequently a far from trivial task, even for the most security conscious of organizations.

Ejaz attended two, weeklong training sessions, one in Athens and another in Riyadh, leading up to the certification examination.

“However, more than the class work, Mohsin’s involvement in project management of our past Security management framework projects (ISMS) is what gave him the field experience needed to score well in the exam,” said Mirza Asrar Baig, CEO of IT Matrix. “Mohsin is just one of a number of security consultants that IT Matrix can make available through in-house resources. We are investing in creating local security management resources, although we will still be bringing in consultants from Europe and the Far East, depending on project size and complexity.”

Baig went on to explain that it has become essential to bridge the communication gap for Saudi client companies in order to guarantee successful project execution.

“A consultant appearing at a customer site for a temporary period of few days is often less than ideal,” Baig said. “It takes time for consultants to establish a relationship and start communicating effectively. As IT Matrix has qualified people who already have strong relationships with the local market, this should ensure efficient and appropriate usage of a visiting consultant’s time.”

A number of Saudi organizations are working toward BS7799 certification. The certification is especially important as WTO membership becomes a reality, with the result that the Saudi economy is liberalized and modernized, and local companies endeavor to compete internationally.

“The value of BS7799 certification, also known as ISO/IEC 17799, is an assurance to firstly the company management and then to its customers that the company is taking the Information Security aspect seriously and has a Information Security risk management plan in place,” Baig explained. “Moreover information security, if perceived rightly is a business enabler. Once the security risks are known and a mitigation plan is in place, corporate management will be comfortable in taking aggressive decisions. Overall this also enhances the efficiency of the company’s operations. In the long run it will play a role in national infrastructure security as the government will be looking towards the private organizations to enhance their security posture and may prefer dealing with ISO/IEC 17799 certified companies.”