Sunteți pe pagina 1din 3

Comment Article

ITAnalysis – Ignorance is not bliss


By Fran Howarth, principal analyst, Quocirca Ltd

dangers of taking work home to personal


As we enter 2009, most of us are tightening our computers that may not have the same security
belts as budgets are slashed and projects put on level as a corporate-issued machine or of
hold. But security threats continue to rise. In downloading software from the internet.
2008, the Internet Theft Resource Center
estimates that 35 million data records were The Office of Management and Budget (OMB),
breached in the US alone, the majority of which part of the US government, issued a report in
were neither encrypted nor protected by a 2007 entitled Common risks impeding the
password. Such a sad state of affairs shows that adequate protection of government information
security practices and awareness remain low, in which it identified the top ten risks. In top
and that this will lead to hackers continuing to position on the list was the risk that security and
prey on organisations. Even as organisations do privacy training is inadequate and poorly aligned
close off the obvious security holes, the number with the different roles and responsibilities of the
of threats that a business faces continues to various personnel involved. The findings of the
grow—from malware attacks to social OMB are no less applicable to private industry.
engineering. Indeed, ENISA, the European Network and
Information Security Agency, concurs with the
Even an organisation that has carefully OMB, stating that awareness of the risks and
established an enterprise-wide security available safeguards is the first line of defence
programme could still find itself at risk. It may for the security of information systems and
have developed security plans, put in place networks.
controls to limit access to systems and
information, as well as proactively managing If that is not enough to convince, then consider
network configurations, and maintaining the following: if your organisation is subject to
operations plans for key information systems. any of the following regulations—HIPAA,
But the best laid plans can have gaps—and Sarbanes-Oxley, FISMA, GLBA or the PCI DSS
numerous studies have shown that people are standards—some level of security awareness
often the weakest link, with the insider threat training for employees is mandatory. Some of
still the greatest for most organisations. If any these requirements are specific in nature, whilst
weaknesses remain, a malicious or careless others stipulate that safeguards need to be put
employee can circumvent poorly policed controls, in place that are appropriate according to the
increasing the risk of unauthorised access to and size and type of organisation.
disclosure, modification or destruction of
sensitive information, or disruption to systems Historically, security awareness training is an
operations and services. area that has received scant attention. The
Business Software Alliance (BSA) recently
What is needed is the encouragement of conducted a survey that found that employee
proactive behaviour, which should of course be awareness was a major challenge for 64% of
backed up with controls. Only when employees respondents, all of which were from large
are made aware of what is expected of them and organisations, when implementing an
understand how inappropriate behaviour can information security programme, with only 16%
negatively impact the organisation are they likely feeling that their employees were adequately
to think about the consequences of their actions. trained. One of the key reasons for this can be
For example, most users are now aware of the found in the results of the Computer crime and
security threats faced when opening an email security survey of 2007 undertaken by the
attachment from an unknown source without Computer Security Institute. It found that almost
scanning it first, but many still fail to realise the half of respondents spend less that 1% of the IT

© 2009 Quocirca Ltd http://www.quocirca.com +44 118 948 3360


Comment Article
security budgets on awareness training. Too that they understand exactly what is expected of
many organisations have had their heads in the them, and why actions are being carried out.
sand.
Any training must address the complete range of
However, security has recently emerged from security issues facing organisations—including
being a grudge purchase to fix a problem that information protection, social engineering,
has occurred and is now increasingly being seen remote worker security, virus and malware
as a business enabler. This is leading many protection, password security, web, email and
organisations to realise the importance of instant messaging security, mobile and phone
security awareness training and Quocirca has security, and physical security. It must also be
noticed a sharp uptick among organisations that flexible enough to be extended to address new
it has spoken to in terms of putting awareness threats and attack vectors as they come to light.
programmes in place. Yet, if so many of the
respondents to the BSA survey referenced above When prioritising budgets for 2009,
feel their employees are inadequately trained, organisations should realise that throwing a
what constitutes best practices? technology solution at a problem is not enough
to secure their assets. Rather, employees need
Quocirca recently spoke to technology vendor to be aware of the part that they have to play in
Symantec about its in-house security awareness minimising the risks that the organisation faces.
training programme for employees, which it is Only when technology, people and processes are
now also offering as a package to external working in sync can an organisation be sure that
organisations. To be effective, any programme its security investments are truly effective.
must encompass all employees in the
organisation, including consultants and
contractors, and must be tailored to provide
training relevant for each role in the
organisation. This is backed up with
conversations with other organisations, which
started their programme by defining the different
roles in the organisation, from those handling
customer payments to IT development staff.

Symantec, and its clients to which it sells


security awareness training programmes,
emphasises that web-based training is not only
the most cost-effective method of training, but it
also brings the best results as employees can
study at a time that they choose, with an audit
trail generated as to where all employees are in
the programme. It must also be impressed that
initial training should be provided for all new
hires, backed up with continual reminders in the
form of posters, screensavers and reminder
cards, as well as conducting post-training
assessments to gauge the effectiveness of the
programme and refresher courses. If the web-
based system is also backed up with
collaborative communication tools, employees
can ask their peers when they do not understand
things, or can interact with dedicated personnel
working within the areas under study to ensure

© 2009 Quocirca Ltd http://www.quocirca.com +44 118 948 3360


Comment Article

About Quocirca
Quocirca is a primary research and analysis company specialising in the business impact of information technology
and communications (ITC). With world-wide, native language reach, Quocirca provides in-depth insights into the
views of buyers and influencers in large, mid-sized and small organisations. Its analyst team is made up of real-
world practitioners with first hand experience of ITC delivery who continuously research and track the industry
and its real usage in the markets.

Through researching perceptions, Quocirca uncovers the real hurdles to technology adoption – the personal and
political aspects of an organisation’s environment and the pressures of the need for demonstrable business value in
any implementation. This capability to uncover and report back on the end-user perceptions in the market enables
Quocirca to advise on the realities of technology adoption, not the promises.

Quocirca research is always pragmatic, business orientated and conducted in the context of the bigger picture. ITC
has the ability to transform businesses and the processes that drive them, but often fails to do so. Quocirca’s
mission is to help organisations improve their success rate in process enablement through better levels of
understanding and the adoption of the correct technologies at the correct time.

Quocirca has a pro-active primary research programme, regularly surveying users, purchasers and resellers of ITC
products and services on emerging, evolving and maturing technologies. Over time, Quocirca has built a picture of
long term investment trends, providing invaluable information for the whole of the ITC community.

Quocirca works with global and local providers of ITC products and services to help them deliver on the promise
that ITC holds for business. Quocirca’s clients include Oracle, Microsoft, IBM, O2, T-Mobile, HP, Xerox, EMC,
Symantec and Cisco, along with other large and medium sized vendors, service providers and more specialist
firms.

Details of Quocirca’s work and the services it offers can be found at


http://www.quocirca.com

© 2009 Quocirca Ltd http://www.quocirca.com +44 118 948 3360

S-ar putea să vă placă și