it wek leader

Security is built on compliance

Data breaches are not the only things on CISOs' minds

Written by IT Week Staff

The headlines in IT security over the past few months have all been centred on the importance of securing corporate data assets. But is the view from the ground any different from the one so often perceived by those outside of the IT industry? The presumption has often been that with the advent of perimeterless networks, and the sharing and storage of data by third parties, IT managers need to prioritise implementing identity and access management systems, and protecting the data itself.

So the recent assertion from IT security chiefs at certain high-profile UK organisations that their primary concern was actually ensuring compliance with regulations such as the Sarbanes-Oxley Act and Payment Card Industry (PCI) standards may come as a surprise.

This emphasis on regulations and legislation does not diminish the importance of data security,­ after all, PCI was created to ensure the secure processing and storage of credit card data. But despite the dramatic warnings spun out by data loss prevention and encryption vendors, the less attention-grabbing activities associated with compliance still dominate the budgets and to-do lists of IT security chiefs.

Given the importance of such activities, it may not be long before more UK organisations establish the role of chief compliance or risk officer to ensure this area has a dedicated owner outside of the IT department.

Tags:

reader comments

related articles

Madeline Bennett

Government U-turns do IT managers no favours

Efforts to improve identity management and curb IT crime are being hindered by government vacillation 13 Mar 2008

 

How to avoid embarrassing leaks

Fostering good staff morale may prove more effective than tough usage rules 07 Mar 2008

Leader: Raising security awareness

IT Week's comment on the stories of the week 14 Feb 2008

Leader: PC crime does pay

IT Week's take on the week's biggest stories 07 Feb 2008

Government savaged over data protection record

Joint Committee on Human Rights criticises "lax standards" 14 Mar 2008

Critics claim first year of WEEE has failed to deliver

Industry insiders claim eWaste recycling schemes are struggling and not enough is being done to promote re-use, but government insists directive remains on track 04 Jul 2008

Government plans to store comms data

Proposed database could mean logs of all phone calls, emails and internet usage are centrally stored 21 May 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation