You are here: silicon.com > Software > Security Strategy

Security Strategy

Compliance brings IT security to the board table

But worms and viruses seen as secondary problem...

Tags: ernst & young

By Dan Ilett

Published: 2 November 2005 16:15 GMT

Companies are choosing to spend more money this year on compliance regulations, such as Sarbanes-Oxley, in preference to combating viruses and worms.

These are the findings from the accounting firm Ernst and Young's annual security report, which said the threat of going to jail - if found guilty of non-compliance - has made information security a boardroom subject.

Nearly two-thirds of 1,300 survey respondents (61 per cent) cited compliance as a top-three primary driver of information security but worms and viruses accounted for only 53 per cent of answers. Meeting business objectives was ranked third (49 per cent).

In a statement, Edwin Bennett, global director of security risk services for the firm, said: "Compliance is proving to be more of a distraction than a catalyst for information security becoming aligned within organisations. One might assume that with the attention information security is receiving due to regulatory compliance, organisations' postures are improving. Unfortunately, this is not happening on a consistent basis."

Two-thirds (62 per cent) said internal control procedures are having the greatest impact on their organisations, followed by privacy concerns (55 per cent). Respondents said they expect requirements to use cryptography to increase from 15 per cent to 20 per cent next year.

Technologies such as voice over IP (VoIP) and open source were found to be a significant security concern in fewer than 20 per cent of firms.

The survey found that the declining cost of wireless connectivity is driving the adoption of mobile technology.

But Bennett added: "Less than half of organisations make provision for general users of information to be trained or made aware of the impact of information security issues with these technologies and fewer still receive training on responding to security incidents."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Production Manager

Keep up to date with the latest equipment, technology industry changes Ensure the workforce is trained in new technology and new techniques Ensure ...

Discipline Lead for M&E (Specifically RAIL)

Responsible for supporting the growing of the business through the achievement of the following key objectives: *Technical leadership; *Setting a ...

Senior J2EE Developer

We offer comprehensive proactive protection from the increasingly prominent threat of mobile viruses, malware, inappropriate content, unsolicited ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: