R E L A T E D   C O N T E N T
ADVERTISEMENT

Untrained users highlighted as security risks

Users given greater IT freedoms, but not security training

Phil Muncaster, IT Week 28 Mar 2008
ADVERTISEMENT

Businesses are giving users greater freedom with corporate IT systems, according to a recent report, but many of those users lack the necessary security training.

The study, conducted by a consortium, led by PricewaterhouseCoopers, on behalf of the Department for Business, Enterprise & Regulatory Reform (BERR), found that firms are placing greater trust in their staff.

Seven out of eight firms now have information security policies in place according to newly released findings from the annual Information Security Breaches Survey (ISBS). Those policies are loosening controls over users.

Fifty four percent said they allow staff to remotely access systems – a rise of 19 per cent from last year's study – while the number of businesses restricting internet access to some staff only has nearly halved from 42 per cent to 24 per cent.

Training staff in security basics is an essential part of any information security strategy, argued Martin Smith, chief executive of The Security Company. "The industry is dominated by technology and technologists … but I've never seen a computer commit a crime, it's always people," he argued.

Smith added that long term behavioural change programmes are the best way to mitigate risk in this area, but most firms are unable to find budget to support such initiatives because "they're hard work and fairly intense"

The importance of security awareness was also highlighted in new figures from security certifications organisation ISC2. The 2008 ISC2 Global Information Workforce Study, set for full release in April, asked 6,523 certified professionals about the importance of certain skills. It found that 90 per cent said a good understanding of security and communication skills are the most important.

See also:

a secure systemSecurity firm Websense has launched a new threat monitoring system  26 Mar 2008
a virus wormAnalyst firm Forrester has some strong words of advice and caution for firms  26 Mar 2008
complianceCompliance initiatives can add impetus to security strategies  19 Mar 2008
fingerprintCompTia research finds big gap between perception and reality  14 Mar 2008

All

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities