
HR, senior execs and staff all off the hook as IT team take the blame...
Published: 6 September 2004 17:25 BST
UK companies are still failing to recognise the importance of properly implemented and managed security, assuming it is just a 'technology issue' rather than a fundamental part of the way their organisation works.
By passing the buck wholesale to the IT department companies are exposing a number of flaws across their organisation - from the top down - and even a tightening of legislation and increased emphasis on accountability and corporate governance has done little to interest the head-in-the-sand 'higher ups' that they should be getting involved and delegating tasks effectively.
According to independent research conducted by Coleman Parkes on behalf of LogicaCMG, 53 per cent of companies entrust the IT department with the sole enforcement of the information security policy.
In addition, 71 per cent of companies rely on the IT department to implement information security policies and approaches - despite the fact that much of the planning should relate to HR and legal issues as much as to the technology in place.
Dave Martin, principal security consultant at LogicaCMG UK, said IT alone is not enough and "process and policy are central to ensuring information security governance". Invariably the IT department, for a number of reasons, are ill-equipped to issue such policy. Nor they would argue should it be their job.
Sal Viveros, SME director at security giant McAfee, believes one of the biggest obstacles to effectively managing security issues centrally from the IT department is the perception of other employees.
Viveros told silicon.com: "A lot of people tend to think of the IT department as being just the guy who takes an age to fix their PC or tells them what they can and cannot have installed on their machine or what machines they have."
Viveros said as a result those in the IT department are often seen as "the bad guys" and coupled with a perceived lack of seniority within the company this makes it difficult for them to dictate, manage and enforce policy.
While staff may sit up and take notice of a policy handed down by HR or a member of senior management, because the trail of accountability and its direct link to discipline procedures is evident, employees may feel less inclined to treat seriously the requests of the IT department.
There may even be a 'the police have all the best drugs' level of resentment whereby employees being told not to do certain things assume those in the IT department handing out such rules are doubtless breaking them themselves and above such policy.
Companies would certainly do well to treat such issues more seriously. Especially as employees, who are rarely governed by stringent enough policies, are generally regarded as the weakest link in the security chain.
And the risks of making mistakes in this area are huge. In a separate study conducted by MORI, also on behalf of LogicaCMG, 83 per cent of investors said a security breach of any kind would impact that companies' share price and 56 per cent they would sell their shares in the event of a breach. And it's not just investors who would take issue with breaches - according to the research 70 per cent of customers would also 'vote with their feet' - boycotting a website if there was the suggestions its security had been compromised.
The fact companies are seemingly doing little about getting on top of security is made all the more surprising by the fact companies are aware of such risks.
A massive 86 per cent of the FTSE 350 companies researched said negative publicity for their company would be the key impact and a similar number (84 per cent) said their brand would be damaged by a security breach.
IT departments often go out and buy technical solu...
Mike Tierney
Boards MUST take responsibility for the 'security'...
IAN WYLIE
Senior execs keep away from the security issue bec...
Anonymous
How many IT departments, give admin rights to the ...
Anonymous
Training will turn receptionists into security gurus
'Office Junior' your biggest security threat
Security: As much about people and places as software
Who knows more about your network - you or the cyber-criminals?
Passwords: Proof that all humans are dull
Revealed: PDA security risks - and what to do about them (part two)
Job Purpose To drive and manage the coordination of core activities across EALA which include contract governance, Quality Assurance, Performance ...
Financial management and control will fall within your remit, as Project Manager, having direct accountability for project budgets of 1-5m. Global ...
Accountability / Responsibility: Security Drive and monitor the security compliance within the organisation. Attend governance meetings. Experience ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...