prison
R E L A T E D   C O N T E N T
ADVERTISEMENT

Board should be liable for breaches, say security profesionals

Websense survey finds IT is not to blame

Rosalie Marshall, IT Week 08 Apr 2008
ADVERTISEMENT

Chief executives of firms that expose customers' confidential data should be put under arrest and jailed, according to a survey conducted by web security firm Websense.

The survey of over one hundred global security professionals was conducted at the annual e-Crime Congress in London.

Over a quarter of respondents said that a jail sentence is the appropriate punishment for a serious data breach, while only three per cent said they did not believe any legally enforced punishment was necessary.

In the 2007 survey, only 74 per cent of the security professionals believed the Board should be responsible for data breaches, but this year the figure increased to 95 per cent. However, less respondents blame IT - only 5 per cent said the IT department should be responsible for breaches, in comparison to last year’s 21 per cent.

This change of opinion could stem from the large number of data breaches that have occurred since last November’s HM revenue and customs loss of 25 million data records which were stored on two discs.

Carrie Hartnell, transformational business programme manager at trade body Intellect, agreed that losses are the outcome of human error rather than because of a failure in technology.

Hartnell argued for a shift in societal and cultural attitudes in how people treat personal data.

“Intellect believes that organisations and government departments should have a co-ordinated approach to data security that recognises the need to educate and train its staff around the handling and use of personal data as well as the appropriate technical security measures,” she added. “They need to ensure that their employees know when they are accessing confidential data and that they understand the policies and procedures for protecting it."

See also:

vaultDetails of over 350,000 customers go missing in the post  07 Apr 2008
Security based on people and process - not technology  03 Apr 2008
vaultProtect Crypto to be bundled with the firm's Protect Premium client  31 Mar 2008
houses of parliamentJoint Committee on Human Rights criticises "lax standards"  14 Mar 2008

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities