Offshoring pushes BS7799 security

Offshoring specialists are using security certification to assure firms that data is safe

Written by Madeline Bennett

When organisations allow outsourcers or other third parties - whether local or offshore - to handle customers' information, they will increasingly demand evidence that this data is protected while offsite. And this requirement is growing as details of high-profile security breaches keep hitting the headlines. One way to ensure good practices for security is to use service providers certified to the BS7799 British security standard - or its international equivalent ISO 17799 - designed to help firms manage and minimise security risks.

Although compliance with the standard is no guarantee of security, it is a sign that a firm takes risk management seriously.

Uptake of the standard has grown massively during its 10-year history, especially in the past few years. In 2002, fewer than 200 organisations worldwide had achieved BS7799 certification, according to the Information Security Management Systems (ISMS) International User Group. Today this number has risen to 1,870.

The results of Ernst & Young's Global Information Security Survey, released last week, also show interest in BS7799 is increasing. Among the 1,300 global organisations surveyed, a quarter had adopted the security standard, while a further 30 percent are planning to do so.

Antony Smyth, information security partner at Ernst & Young, said some firms believe that achieving certification would be too complicated, so many are following its guidelines without getting formally certified. "We're all better off if we have recognisable public-domain standards to work to," he added. According to the ISMS group, Japan has by far the most certificates for one country, at 1,080. In second place is the UK with 215.

One of the countries with the fastest-growing uptake is India, in third place with 131 certified firms - up from 28 last April. LogicaCMG, which last month announced that its facilities in Bangalore had achieved BS7799 certification, said it is evidence of good business practice and proof the firm has implemented good security schemes.

"Most of our clients are European, so we need to show we're operating in line with best UK and European security practice," said Dave Martin, managing consultant at the firm. "We're also handling personal information for clients in the financial sector, so they want to make sure we're operating legally under FSA rules, and under the UK's Data Protection Act."

Uptake of the standard could become more important for offshore firms in future. Martin noted predictions that offshore facilities without proof of good security systems are likely to lose business and close within the next five years. Martin added that cultural differences are also a challenge. "People in India want to be helpful. So if you turn up without a security badge the guard will still let you in - this needs to be changed," he said.

Tags:

reader comments

related articles

Standardised IT offers more value

Research advises firms to follow standards 28 Jun 2005

 

Regulation will not ease product flaws

Should IT security be regulated? 26 Oct 2005

Security policy and governance

TWENTY years ago security was considered an overhead. But after two decades of education and example it is now considered a vital part of operating practice. 30 Jun 2005

Review 2007: Outsourcing

More and more organisations are turning to specialist IT service providers - we look back at the year's top stories 20 Dec 2007

Broadband to be provided via sewers

Technology not a flash in the pan 25 Jan 2008

Centrica reviewing offshore wind plans as cost fears mount

Industry insists outlook remains upbeat, but credit crunch and rising construction bills are prompting growing numbers of developers to review projects 17 Nov 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation