Related Links

Related Stories

  • RSA Europe: ISF President warns mobile phones may be next platform for security threats
    Speaking with Infosecurity at the RSA Europe conference in London, Professor Howard Schmidt, the president of the Information Security Forum (ISF) said that mobile phones - rather than other high-profile platforms such as cloud computing - are the likely source of the next generation of security threats facing companies.
  • ISF details top ten future IT security threats
    Cybercrime is at the top of the Information Security Forum's (ISF) Threat Horizon list for 2011, which highlights the growth of `crimeware as a service' offered by criminal gangs, along with infiltration into organisations to carry out insider attacks.
  • Information security and the recession
    As the recession continues to chew into budgets, and cyber criminals see increased opportunity for looting, CIOs must ensure that information security defences remain strong and affordable, even if this means a little bargaining. Stephen Pritchard looks at how organisations can negotiate the rough seas ahead.
  • Infosecurity work with Tory MPs to develop data security working group
    Infosecurity magazine were honoured to receive an invitation from MPs Eleanor Laing and Nick Herbert to visit the Houses of Parliament this week, to discuss the Conservative party’s data security agenda.
  • Search for security
    With more than 30 000 web pages being infected every day, search engine results could increasingly lead to malware infection. Kari Larsen asks what the search engines are doing to mitigate security threats, and how users can protect themselves.

News

RSA Europe: We need revocable personal data says ISF president

22 October 2009

Speaking at the RSA Europe conference in London this week, ISF president Professor Howard Schmidt said that there is now a need for people to be able to revoke the personal data they present for identification and credit-worthiness to financial institutions.

The problem, he explained, is if someone gives their personal credentials to a bank or credit card issuer - or even a mobile phone company - those details are checked and then stored, perhaps for ever.

"Even if I close the account and move to other bank or mobile phone service provider, those details stay on record. There really needs to be some system that allows data to have a time limit attached to it, and, when that limit passes, the data is destroyed", he said.

Moving on to the subject of the IT security industry, Professor Schmidt said that his own observations, as well as those of his members, suggests that the bulk of the effects of the current recession have yet to be experienced in the IT industry.

"I've only heard of one person in IT security losing their job owing to cut-backs, and that was a special case", he said, adding that whilst budgets are being trimmed, IT security seems to be relatively immune.

There appears, he said, to be an understanding that IT security is a very necessary part of the IT equation and, because of this, whilst some IT security projects are being placed on hold, they are usually only being placed on a back burner until such times as the firm can afford to spend the money.

"That's a lot different to having a project cancelled, as is happening in other sectors of the IT industry",  the ISF president said.

"The big question, however, seems to be - can we continue to spend the money on outsourcing of IT security that we have been doing?"

"My observations suggest yes, as vendors and service providers are now discounting their prices to meet client budgets."

Professor Schmidt went on to say that, as vendors and service providers cut their prices, many are actually seeing new customers coming on board who would previously been dissuaded by price.

Overall, he explained, this means that some IT security suppliers - though they are dealing with more customers at lower prices - are actually making as much, if not more, money than they would have done at previous prices.

 

This article is featured in:
Compliance and Policy Identity and Access Management

 

Comment on this article

You must be registered and logged in to leave a comment about this article.