October 07, 2008
Home
About
Submit Press Release
PR Firms
Editors/Journalists
Search Archives
 
News Releases by Category  
News by Country  
News by MSA  
All News for Today  
Browse News by Day  
News by Trackbacks  
All Press Releases for March 31, 2008 Subscribe to this News Feed  
 

Two-Thirds Of Employees Have To Bypass Data Security Controls To Do Their Jobs, Survey Finds

Download this press release as an Adobe PDF document.

Sixty-eight percent of employees admit to bypassing their employers' information security controls in order to do their jobs, according to new research from IT Governance Limited. This suggests that managers are failing to understand the correct balance between the confidentiality and availability of information, and that best practice standards should be more widely adopted.

Ely, England (PRWEB) March 31, 2008 -- Sixty-eight percent of employees admit to bypassing their employers' information security controls in order to do their jobs, according to new research from IT Governance Limited (http://www.itgovernance.co.uk/). This finding suggests that, even in some of the most sophisticated and security-conscious organisations, managers are failing to understand the correct balance between the confidentiality and availability of information. By implementing the wrong policies and procedures, they are potentially putting their organisations at risk and may be undermining the legitimacy of information security in employees' eyes.

IT Governance Limited is the one-stop shop for books, tools, training and consultancy on Governance, Risk and Compliance. In February 2008, it polled 130 technology and compliance professionals on issues concerning the UK Data Protection Act ('DPA'). The respondents included some of the best informed professionals in this area, as evidenced by the high proportion of organisations with independently certified data security measures. The full findings of this survey will be published next month in 'Data Breaches: Trends, Costs and Best Practices' (http://www.itgovernance.co.uk/products/1615), the first of IT Governance's new series of Best Practice Reports (http://www.itgovernance.co.uk/best-practice-reports.aspx).

The research found that most organisations appeared aware of their responsibilities under the DPA, with over 80 percent having a data controller or someone responsible for maintaining privacy. Eighty-two percent of organisations had clear policies and procedures for protecting personal data, including documented procedures (68 percent of organisations), formal procedures (57 percent) and informal procedures (24 percent). Twenty-one percent had policies and procedures certified to best practice standards, such as ISO27001 (http://www.itgovernance.co.uk/iso27001.aspx), indicating that respondents represented organisations that are particularly well managed in the field of information security. Nevertheless, the high incidence of employees deliberately circumventing policies and procedures indicates that many of the measures introduced by management are unduly obstructive, either in design or implementation.

Organisations also differ in the comprehensiveness of their data security regimes. While 89 percent cover access to personal data, only 56 percent govern detecting and reporting data losses, while just 39 percent extend to correcting data loss incidents.

The need for DPA compliance is clear, with 96 percent of the organisations represented holding personal information about customers, patients or other individuals. Of these, 56 percent hold payment card or other financial information; 39 percent hold sensitive personal information, such as ethnicity, religion or political affiliation; and 36 percent hold medical information. However, only 55 percent of employees handling personal data have been trained in their legal responsibilities in respect of this information.

Alan Calder, Chief Executive of IT Governance, said, "Under the Data Protection Act, it is a legal requirement for organisations to safeguard personal information, but this can only be achieved with the support of employees. By imposing ill-considered procedures, many organisations leave people little option but to break the rules if they are to do their jobs. This not only leaves businesses vulnerable to data breaches and fines, but also does lasting damage to the way employees regard infosecurity. If more organisations followed best practice standards like ISO27001, they would be doing a service to their customers, employees and themselves by making data security workable and readily adopted."

Priced at £195.00/$386.10/€253.50, Data Breaches: Trends, Costs and Best Practices will be published by IT Governance on 15 April 2008 and can be pre-ordered from http://www.itgovernance.co.uk/products/1615 at a specially discounted price.

NOTES TO EDITORS

IT Governance Ltd is the one-stop shop for books, tools, training and consultancy for Governance, Risk Management and Compliance. It is a leading authority on data security and IT governance for business and the public sector. IT Governance is 'non-geek', approaching IT issues from a non-technology background and talking to management in its own language. Its customer base spans Europe, the Americas, the Middle East and Asia. More information is available at www.itgovernance.co.uk.

Alan Calder is an international authority on information security management. He led the world's first successful implementation of BS7799, the information security management standard upon which ISO27001 is based, and wrote the definitive compliance guide for this standard, 'IT Governance: A Manager's Guide to Data Security and BS7799/ISO17799'. The 3rd edition of this book is the basis for the UK Open University's postgraduate course on Information Security. He is a consultant to companies including Cisco. He regularly blogs on IT security issues at http://alancalder.blogspot.com/.

# # #

Trackback URL: http://www.prweb.com/pingpr.php/U3VtbS1UaGlyLVN1bW0tSGFsZi1TdW1tLVplcm8=


See the original story at: http://www.prweb.com/releases/2008/03/prweb810124.htm
This press release was posted by the following PR Firm
80:20 Communications Limited (View Listing in Directory of PR Firms)
 
Other Releases by this Member
Email this story to a colleague
Printer Friendly Version
Bookmark with del.icio.us
Bookmark with Y!MyWeb
Submit to Digg
MARC CORNELIUS
IT Governance Limited
+44-20-7924-7576
Email us Here

Alan Calder
Uploaded: Feb 1, 2008
File Name: AlanCalder2Dec04.JPG

If you have any questions regarding information in these press releases please contact the company listed in the press release. Please do not contact PRWeb. We will be unable to assist you with your inquiry. PRWeb disclaims any content contained in these release. Our complete disclaimer appears here.
 
Disclaimer: If you have any questions regarding information in these press releases please contact the company listed in the press release.
Please do not contact PRWeb®. We will be unable to assist you with your inquiry.
PRWeb® disclaims any content contained in these releases. Our complete disclaimer appears here.

© Copyright 1997-2007, Vocus PRW Holdings, LLC.
Vocus, PRWeb and Publicity Wire are trademarks or registered trademarks of Vocus, Inc. or Vocus PRW Holdings, LLC.

Terms of Service | Privacy Policy | Copyright