Thursday, April 23, 2009

Culture of ignorance threatens IT security

New figures released this week reveal that half of UK security managers are worried about end-users’ lack of security awareness.

A poll conducted by Infosex Europe of 700 security professionals reveals that the biggest concerns of security managers are a lack of security training for end-users, and an unsupportive company culture when it comes to security. Further, 46% of respondents have concerns over the poor understanding of employees over security policy, made worse by a lack of accountability over security.

A survey of security professionals stating that businesses do not have secure enough systems is hardly surprising, but these figures are all the more alarming when taken into account with the paper published by independent security expert group Jericho Forum this week. The paper stated that cloud computing has massive implications for security, and that the expansion of the cloud throws up all sorts of possible security breaches.

In amongst those security threats are loss of data confidentiality and integrity, which presents a major concern for businesses. The Jericho Forum advocates a thorough approach to security in cloud computing that starts from the beginning, rather than ad hoc solutions as and when problems arise.

When it comes to cloud computing, a holistic approach is necessary; there is no point implementing the technology without having networks secured first. Additionally, staff worldwide need to understand the security implications and maximise cloud computing. Perhaps most important of all is the need to continually ensure that, with all data stored in the cloud, it is safe. It is nearly impossible to ensure this without round-the-clock monitoring. Technology can only do so much human beings can ensure security is consistently working. The problem with automatic security alerts is they often come once the threat has entered the system too late to prevent data loss.

Security blogs:

http://www.itsecurity.com/blog/

http://www.itsecurityportal.com/

http://theitsecurityguy.blogspot.com/

http://newsteam.scmagazineblogs.com/

No comments: