Smith: Above all, it's about accountability

Managers must face security responsibility

Managers must face security responsibilityImplement secure access and remove data transfer, say experts

Written by Janie Davies

There needs to be clear accountability for data protection within organisations to ensure security of information, according to experts in the public sector.

Data protection will improve when senior corporate officers’ jobs or freedom are at risk, deputy information commissioner David Smith told the Westminster eForum on Security last week.

“It is about scrutiny, policing, data deletion and data minimisation, but above all it is about accountability,” he said.

Smith said that information assets should be allocated to a senior officer, as well as board-level accountability, scrutiny, public statements about the way the organisation handles data, effective regulation and annual assessments.

“You need to decide who should be shown the door if things go wrong, and if you cannot answer that, there is a problem that needs to be addressed,” he said.

“While penalties will change the culture to some extent, I do not think the value of the fines matters; reputation is the driver.”

The issue is not being taken seriously enough by managers and many recent breaches could have been avoided, according to Francis Aldhouse, consultant at legal firm Bird & Bird.

“I agree that we need a culture change. We have seen examples where data protection has not been a management priority, so conscious decisions have been made not to address the significance of the issue,” he said.

“I would like to see criminal penalties ­ on organisations and individuals ­ for failing to comply with regulations. The only way is to make it possible for managers to suffer.”

Phillip Wright, a partner at PricewaterhouseCoopers, said: “The biggest area of risk is data transfer. We should be looking at minimising it and eventually phasing it out.”

Carrie Hartnell, programme manager for information and security at industry trade association Intellect, said: “Regaining customer and consumer confidence is vital, especially as we are moving towards putting more services online.”

Hartnell said Intellect thought that legislation requiring data breach reporting was an inevitable step.

“We believe that there will be a requirement, not just an option, to report data breaches in future,” she said.

reader comments

related articles

laptop userSecurity

Web shoppers more aware of security

But accessibility and attractive design rank higher than data protection concerns 08 Jul 2008

 

Lords call for e-crime shakeup

Fraud should be reported to police, not banks and consumers must have more protection, says Committee 08 Jul 2008

ICO: we need new data protection laws

Richard Thomas says data protection laws are seen as out of date and bureaucratic 07 Jul 2008

Google must surrender its users' personal information to Viacom

A US court has ruled that Google must provide Viacom with details of users who have watched YouTube videos 04 Jul 2008

Reports reveal poor security practices behind data losses

Data handling review spells out what the government must do to regain the public’s confidence 02 Jul 2008

HMRC blunder leads to further private data leak

Error with PAYE system left business details exposed online 03 Jul 2008

Security professionals aim to end data breaches

Increasing sensitivity about corporate repuations is spurring actions on leaks 25 Apr 2008

ICO given stronger data protection powers

Lib-Dem's compromise gets data protection breaches on to the statute books 09 May 2008

Information Commissioner gets stronger powers

The Information Commissioner has finally got his wish, increased powers to tackle data breaches 09 May 2008

related whitepapers

today's top stories

Body Shop rolls out PCI system

Retailer hopes to benefit from improved customer data analysis 07 Oct 2008

Where to offshore (and why not here?)

Tholons, the research firm founded by well-known offshoring guru Avinash Vashistha , has just published some new research in Global Services magazine... 07 Oct 2008

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

The pIT stop Q&A: How can I measure the business success of IT applications?

Ou expert panel answers readers' real-life IT questions 07 Oct 2008

National Identity Fraud Prevention Week

Every Monday seems to mark the beginning of a new awareness drive and this week’s theme has particular importance to small businesses... 06 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

Ethernet cableVideo

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

Podcast imageAudio

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Latest in-depth articles

Features

How to ensure progress in programming

Best practice advice from Forrester Research 02 Oct 2008

BT workersAnalysis

Wanted: a viable model for fibre

While other European countries are pressing ahead with fibre rollouts, progress in the UK is being held back as the debate over who will foot the bill drags on, writes Dave Bailey 02 Oct 2008

Advertisement

Primary Navigation