ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/registration.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Infosec 08: Make security part of corporate culture

Organisations must make privacy a part of all projects, and put data security in the hands of senior management, according to a new report.

By Nicole Kobie, 23 Apr 2008 at 15:59

Preventing the next data breach requires corporations to undergo a complete change of culture when it comes to security, according to a new study.

The report, produced by the Cyber Security Knowledge Transfer Network (KTN) and released during the Infosec 2008 show, examined how businesses can make the data they hold more secure.

It said that organisations must be aware of the importance of data security, because of the legal and financial implications, as well as the ethical ones.

The KTN advised three steps. First, organisations must take responsibility for securing data. Businesses clearly see the benefits IT offers, but sometimes miss the downsides, explained KTN's director, Nigel Jones. "This is a set of problems we didn't expect," Jones told IT PRO. "Now we have to reverse engineer to workout these vulnerabilities."

Second, privacy must be built into all stages of product development, from the initial planning through to audits afterwards. "You need a whole life view of privacy throughout the system," said Jones.

Third, the responsibility for assuring private data is secure must rest with the top members of the company - not the bottom. Jones said that solving data insecurity isn't just about finding the right tech, but about seeing data as having value and as something worth protecting. "It's not going to require some large-scale procurement. You need to make someone more senior responsible for it," he said. "It's a culture change."

He added: "It's about understanding the value of information, giving it monetary value."

Following from that, the report advised businesses against delegating such responsibilities to a junior staff member - it's often been junior members of staff held responsible for recent data breaches. Jones said every company - large and small - must have one person responsible for further moving the issue into the spotlight.

"They must be high profile... but they don't have to be a security person," he explained. "Data and information is not just the security department's concern."

He added: "It's more important that the person has the ear of decision makers in the company."

Jones acknowledged that security has moved up the business agenda lately, following a series of high-profile data breaches.

But it said it will take time to solve these issues. "It's slow to change culture," he said. He called on universities to teach software development in a way which focuses on security, and for governments to enforce the legal aspects.

When it comes down to it, he again stressed that securing data is more about culture. "We need to get people to want to look after it like it was their own personal possession," Jones said.

For more Infosec 2008 coverage, see IT PRO's roundup page here.

Email to a friend

Print this page

Social Bookmark this article: What is this?

Be the first to comment on this article

You need to Login or Register to comment.

advertisement
advertisement

    Latest News Videos in Security

Video: Q&A with Richard Archdeacon, Symantec

Play Video: Q&A with Richard Archdeacon, Symantec   Play

IT PRO speaks to Richard Archdeacon, director, global services, at the information security software vendor Symantec.

 

    White papers

Want more background on today's hottest IT trends?

Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.

    Register for IT PRO

You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Advertisement