
Bosses – lead from the front, says report
Published: 3 February 2004 08:45 GMT
UK organisations are failing to communicate the business importance of security policies to staff, according to a new survey, with most staff reporting that they regarded security as a technical issue. This situation is likely to lead to security breaches, warned the National Computing Centre (NCC), which published the survey results on Thursday.
The NCC, an independent research organisation with members that include universities, government bodies, small businesses and enterprises, said organisations' IT security culture is not keeping pace with their growing reliance on computing systems, with security breaches leading to financial losses and business disruption.
"IT managers need to convey this message in business terms, by highlighting the financial impact of information security failures," said NCC chief executive Michael Gough, in a statement. "The key issue here is raising the profile of information and IT security so that it is on the business agenda, not just the IT agenda."
About 80 per cent of UK organisations have a formal IT security policy, the NCC said. The survey found a direct relationship between the security awareness of top managers and that of the staff generally, suggesting that support from the upper echelons of management is necessary to create a strong IT security culture in the rest of the company.
Particular techniques of maintaining security awareness also appeared to make a difference, the NCC said. Organisations that used an ongoing, varied process to keep staff up to date on IT security issues reported the highest levels of staff awareness.
The group recommended that organisations take tough disciplinary action for internet abuse, encourage genuine management involvement in IT security issues and include IT security issues in senior management performance appraisals.
Matthew Broersma writes for ZDNet UK
We are the UK's leading provider of software systems, services and infrastructure to schools, colleges and universities. Work in an open and ...
Perform a quarterly review and action updates to this plan where required. In depth exposure to a high profile global venture. Communicate regularly ...
Strategic Influencing - Uses strategic Influencing to build commitment to their growth agenda and to influence others without using hierarchical ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...