
"A security policy is a very difficult thing to write and maintain..."
By Pia Heikkila
Published: 18 April 2002 13:15 GMT
UK business is failing to make even the first step towards security, according to a study released by the Department of Trade and Industry this week, but the remedy may not be as straightforward as people think.
The DTI survey found only 25 per cent of UK companies have a security policy in place. Such a policy is vital to tell users what they can and cannot do with their machines. Without this most basic step other security measures are likely to be ineffective.
However, the security industry has now acknowledged that security policies are too complicated for IT managers because they require constant updating to reflect the changing nature of a company's IT infrastructure.
David Hofacker, UK country manager for a software company Extended Systems, said: "The figures from the study are not a surprise because security policy is a very difficult thing to write and maintain. IT managers are struggling to update the policies because things change so fast and they have their hands full."
Jason Holloway, UK managing director of Finnish security company F-secure, said: "Security policies should be constantly re-written, not just be over and done with. Companies should invest money on getting it done properly and if they cannot do it in-house, they should get someone else to do it."
Dag Ströman, technical consultant at RSA Security, said vendors cannot write the policies for IT departments: "It's a bit like buying a car. They come with manuals but no-one can ensure safe driving except the driver."
Working within the Market Risk Team, these roles will be responsible for analysing exposure to market risks (interest rates, foreign exchange, ...
Security AnalystLeedsNew organisation. Unique issues. An opportunity to create a better future for children. The Child Maintenance and Enforcement ...
Configuration and maintenance of Nagios system monitoring Citrix XenServer and RSA authentication manager administration . Duties and ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business