IT departments being passed the security buck

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

UK companies are still failing to recognise the importance of properly implemented and managed security, assuming it is just a 'technology issue' rather than a fundamental part of the way their organisation works.

By passing the buck wholesale to the IT department companies are exposing a number of flaws across their organisation -- from the top down -- and even a tightening of legislation and increased emphasis on accountability and corporate governance has done little to interest the head-in-the-sand 'higher ups' that they should be getting involved and delegating tasks effectively.

According to independent research conducted by Coleman Parkes on behalf of LogicaCMG, 53 percent of companies entrust the IT department with the sole enforcement of the information security policy.

In addition, 71 percent of companies rely on the IT department to implement information security policies and approaches -- despite the fact that much of the planning should relate to HR and legal issues as much as to the technology in place.

Dave Martin, principal security consultant at LogicaCMG UK, said IT alone is not enough and "process and policy are central to ensuring information security governance". Invariably the IT department, for a number of reasons, are ill-equipped to issue such policy. Nor they would argue should it be their job.

Sal Viveros, SME director at security giant McAfee, believes one of the biggest obstacles to effectively managing security issues centrally from the IT department is the perception of other employees.

Viveros told silicon.com: "A lot of people tend to think of the IT department as being just the guy who takes an age to fix their PC or tells them what they can and cannot have installed on their machine or what machines they have."

Viveros said as a result those in the IT department are often seen as "the bad guys" and coupled with a perceived lack of seniority within the company this makes it difficult for them to dictate, manage and enforce policy.

While staff may sit up and take notice of a policy handed down by HR or a member of senior management, because the trail of accountability and its direct link to discipline procedures is evident, employees may feel less inclined to treat seriously the requests of the IT department.

There may even be a 'the police have all the best drugs' level of resentment whereby employees being told not to do certain things assume those in the IT department handing out such rules are doubtless breaking them themselves and above such policy.

The issues involved are serious. Employees, who are rarely governed by stringent enough policies, are generally regarded as the weakest link in the security chain.

And the risks of making mistakes in this area are huge. In a separate study conducted by MORI, also on behalf of LogicaCMG, 83 percent of investors said a security breach of any kind would impact that companies' share price and 56 percent they would sell their shares in the event of a breach. And it's not just investors who would take issue with breaches -- according to the research 70 percent of customers would also 'vote with their feet' and boycot a Web site if there was the suggestions its security had been compromised.

The fact companies are seemingly doing little about getting on top of security is made all the more surprising by the fact companies are aware of such risks.

A massive 86 percent of the FTSE 350 companies researched said negative publicity for their company would be the key impact and a similar number (84 percent) said their brand would be damaged by a security breach.

Talkback

I agree with you, many companies do not know what the staff throws out in the waste.

A good Security Policy must encompass all aspects of the the business, including HR, IT and Management.

The process starts with the vetting of staff by the HR department and continual security awareness sessions from then on.

Strong information security policies must be in place and be seen to work.

via Facebook 7 September, 2004 10:25
Reply

We agree with the point being made but the emphasis should not be on the IT, HR or even the legal department – it needs to be on the board members of an organisation. It is imperative that the board understands the importance of the issues concerning IT security and make it clear that they support and adhere to the IT policies that are in place.

Policies, and the procedures that underpin them, are the only way to ensure that employees know where they stand and what is expected of them. Unless you state and communicate effectively what is acceptable use of IT, employees will not know they are doing anything wrong. If that communication comes from the top then there is no excuse for employee unawareness.

via Facebook 9 September, 2004 16:20
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

BrownieBoy

@Jack, > Works really well for thieves.... Nice attempt to deflect the argument by tossing in a point that's totally irrelevant, even it were...

5 hours ago by BrownieBoy on AMD Ultrathins to challenge Intel Ultrabooks
bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

8 hours ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

11 hours ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

15 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

1 day ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

1 day ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

1 day ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

2 days ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint