Related Stories

  • ICO to make data protection compliance easier
    The Information Commissioner’s Office (ICO) has released a new guide on data protection containing practical advice on data protection compliance. New Information Commissioner Christopher Graham also talked to Infosecurity on the challenges facing ICO.
  • Government behind on information security – Eleanor Laing
    As more and more fundamental tasks in society are carried out online, information security is becoming increasingly important, but the government is not moving fast enough, according to Conservatives MP Eleanor Laing.
  • PCI-DSS compliance does not always guarantee security
    Newswire reports that some of the firms who have experienced data breaches in recent months were PCI-DSS-compliant highlights the fact that - even if a company has passed the standard on the regulatory front - this does not guarantee the integrity of their IT security systems, says Tufin Technologies, the security lifecycle management specialist.
  • HSBC hit by three million pound fine
    A three million pounds-plus fine imposed on three of HSBC's divisions for failing to adequately protect customer data could easily have been avoided if the banking group has made use of digital data vaulting technology, says Cyber-Ark.
  • Flattery will get you everywhere - social engineering and information security
    The widespread availability of personal information, along with employees being exposed to more data than they need to know, is making it easier for hackers to bypass the ‘human firewall’ of information security. SA Mathieson reports on the rising threat of social engineering

News

Infosecurity Europe: Employee awareness of security is “dangerously immature” says (ISC)2’s Colley

30 April 2009

John Colley, managing director of (ISC)2 EMEA lamented the lack of security is company culture in his talk ‘Are we getting the basics right’ at Infosecurity Europe this year.

“My contention is that data losses are not down to technology or [cybercriminals] doing clever things,” Colley remarked, putting recent data breaches down to a lack of employee awareness.

Colley emphasised that any organisation must have policies and standards, though he added that this was “a bit of a cop out as everything else could be rolled up under that”.

He observed that there should be “some sort of system/process/procedures to ensure the policy and standards can be met”, as well as communications, education and training, and a review process:  “If you don’t know it’s working, you’re going by trust.”

He added that there must be corrective action.

At a more basic level Colley noted, there should be, top management commitment and access control.

“It sounds so simple,” he said “but I’ve worked in a number of major banks and access control was a nightmare.”

Colley remarked that recent high profile breaches were “not really technology breaches but people doing silly things…It’s not about very clever technology, it’s about businesses”.

Colley pulled statistics from a recent (ISC)2 survey, which found that 72% of respondents knew of their company having a security policy, and just 63% of these confirming that their organisation tracks the enforcement of their policy.

The survey also found that the obstacles preventing compliance with an organisation’s security included a lack of training for 48%, of respondents, the culture of the organisation for 48% and poor communications for 46%. Interestingly, just 22% of the professionals that were questioned put their obstacles down to a lack of budget.

When asked how the respondents’ company educates customers and suppliers on how to interact safely, 64% replied that there was a contractual obligation. Colley noted this was ineffective as it was akin to saying “We‘re gonna sue you if you do something wrong so make sure you don’t do something wrong”.

Colley warned that recent breaches were “all about company culture, it’s all about poor understanding of policy, it’s all about accountability not being defined,” and added that “employee awareness is dangerously immature.”

“Security is not the security department’s responsibility. It goes much deeper than that,” he concluded, saying that “organisations should be creating an environment where the security policies actually help the business – where they are not ignored.”

 

 

This article is featured in:
Compliance and Policy Data Loss

 

Comment on this article

You must be registered and logged in to leave a comment about this article.