Share

Related Links

  • ISAF
  • Elsevier Ltd is not responsible for the content of external websites.

Related Stories

  • Cisco warns of fresh Webex vulnerabilities
    Cisco has warned users of new vulnerabilities in its Webex conferencing system, the firm which it acquired in March 2007.
  • (ISC)2 EMEA director warns about DIY cloud computing
    With interest in cloud computing taking off, especially now that Microsoft is about to formally open its Azure cloud service on 1 January, the EMEA director of (ISC)2, the not-for-profit IT security education and certification body, has warned about the dangers of the technology
  • Unauthorised local authority staff access to personal data is inevitable
    Reports in Computer Weekly that a number of local authorities are sacking or disciplining staff for viewing personal data on the Department for Work and Pension's Customer Information System (CIS) comes as no surprise, says Cyber-Ark, but merely serves to highlight the need for highly privileged access to this kind of data.
  • 2012 Threat Predictions: An Industry Roundup
    We asked more than 20 security companies and security experts for their threat predictions for 2012. The intent? To find what the security industry in general expects to see next year. The results are not scientific, but certainly indicative of what business can expect in 2012.
  • (ISC)² says governments need infosed community to drive strategy and standards
    (ISC)², the not-for-profit IT security association, says that, against a backdrop of more and more governments recognising the need for cyber security strategies, they now need to recognize the requirement for internationally recognised skills, principals and practices to tackle what is a very sophisticated global threat landscape.

Top 5 Stories

News

ISAF raising awareness of main threats to online security

18 February 2010

The Information Security Awareness Forum (ISAF) has announced a rolling calendar of themes for this year, where each month sees a focus on a main threat to information security.

The ISAF, which celebrates its second birthday this month, was born out of the ISSA-UK Advisory Board and is a cross-industry initiative set up to raise awareness of information security.

According to the forum, many of its member organisations will be working on awareness activities in the schedule, so magnifying the message.

The forum says that, like insurance, information security tends to be interesting only to people when something bad happens. Despite this, the industry association – which has more than 20 members – claims it is quite easy to take simple steps to reduce the likelihood of the security victim being you.

David King, the ISAF's chairperson, said that the calendar will help the member organisations and others in the industry co-ordinate their awareness activities around specific themes.

"This increased focus will help create opportunities for partnership and assist in planning and collaboration to raise awareness of good security practices", he said.

King's comments were echoed by Jim Norton, chairperson of the IET IT Policy Panel, who said he welcomed the initiative.

"Creative use of information communications technology continues to bring great benefits to our Society, but every silver lining has a dark cloud", he said. "It is vital that we continue to raise awareness of the risks involved and I commend ISAF's comprehensive approach to this", he added.

John Colley, managing director of (ISC)2 EMEA, said that, as founding members of the ISAF, (ISC)2 welcomes this initiative.

"Too often awareness is ineffective due to the fact that too many messages are being communicated to too many people. By focusing on specific issues each month, the calendar provides a means to deliver these important messages to the people that really need to understand them", he said.

The campaign kicked off last month with a social engineering and phishing theme, followed by mobile device security this month and child protection plus online ID security in March.

The programme continues in April with a general security awareness theme and, in May, the focus will be security compliance and the law, followed by identity protection in June and convergence/physical protection issues in July.

When August comes around, the ISAF theme of risk management and how to assess online dangers, followed by the September theme of business continuity and backups, segueing into corporate governance in October, and crime in November.

And the monthly themes are rounded out in December with malware being the topic of discussion.

Malicious software, says the forum, is a constant threat on the internet and installs itself on a victim's computer and then undertakes some unwanted action, without the victim's consent.

This article is featured in:
Compliance and Policy  • Security Training and Education

 

Comment on this article

You must be registered and logged in to leave a comment about this article.