Smith: Above all, it's about accountability

Managers must face security responsibility

Managers must face security responsibilityImplement secure access and remove data transfer, say experts

Written by Janie Davies

There needs to be clear accountability for data protection within organisations to ensure security of information, according to experts in the public sector.

Data protection will improve when senior corporate officers’ jobs or freedom are at risk, deputy information commissioner David Smith told the Westminster eForum on Security last week.

“It is about scrutiny, policing, data deletion and data minimisation, but above all it is about accountability,” he said.

Smith said that information assets should be allocated to a senior officer, as well as board-level accountability, scrutiny, public statements about the way the organisation handles data, effective regulation and annual assessments.

“You need to decide who should be shown the door if things go wrong, and if you cannot answer that, there is a problem that needs to be addressed,” he said.

“While penalties will change the culture to some extent, I do not think the value of the fines matters; reputation is the driver.”

The issue is not being taken seriously enough by managers and many recent breaches could have been avoided, according to Francis Aldhouse, consultant at legal firm Bird & Bird.

“I agree that we need a culture change. We have seen examples where data protection has not been a management priority, so conscious decisions have been made not to address the significance of the issue,” he said.

“I would like to see criminal penalties ­ on organisations and individuals ­ for failing to comply with regulations. The only way is to make it possible for managers to suffer.”

Phillip Wright, a partner at PricewaterhouseCoopers, said: “The biggest area of risk is data transfer. We should be looking at minimising it and eventually phasing it out.”

Carrie Hartnell, programme manager for information and security at industry trade association Intellect, said: “Regaining customer and consumer confidence is vital, especially as we are moving towards putting more services online.”

Hartnell said Intellect thought that legislation requiring data breach reporting was an inevitable step.

“We believe that there will be a requirement, not just an option, to report data breaches in future,” she said.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

laptop userSecurity

Web shoppers more aware of security

But accessibility and attractive design rank higher than data protection concerns 08 Jul 2008

 

Lords call for e-crime shakeup

Fraud should be reported to police, not banks and consumers must have more protection, says Committee 08 Jul 2008

ICO: we need new data protection laws

Richard Thomas says data protection laws are seen as out of date and bureaucratic 07 Jul 2008

Google must surrender its users' personal information to Viacom

A US court has ruled that Google must provide Viacom with details of users who have watched YouTube videos 04 Jul 2008

Reports reveal poor security practices behind data losses

Data handling review spells out what the government must do to regain the public’s confidence 02 Jul 2008

HMRC blunder leads to further private data leak

Error with PAYE system left business details exposed online 03 Jul 2008

ICO wins backing for £500k data breach fines

Ministry of Justice agrees on maximum amount organisations can be fined 13 Jan 2010

Protests at government surveillance grow

1,500 attend public meeting to warn of database dangers 02 Mar 2009

Report data breaches or risk tougher sanctions, warns ICO

The Information Commissioner’s Office has warned organisations that they may face tougher sanctions if they fail to report security breaches which subsequently come to light 29 Jan 2010

related whitepapers

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation