PC user at desk

Security awareness-raising forum is launched

New organisation aims to reduce human failings and improve organisations' security

Written by Phil Muncaster

A major new initiative was launched today designed to reduce information security failures in organisations by raising security awareness levels.

The Information Security Awareness Forum (ISAF) was commissioned by the advisory board of the Information Systems Security Association (ISSA) and is comprised of professional IT bodies such as the British Computer Society (BCS), Information Seecurity Forum and the Institute of Information Security Professionals (IISP).

Security awareness is seen as one of the key contributors to firms' security failures, so the ISAF will aim to utilise the significant resources of its member organisations to produce clear and consistent messages around IT security, according to ISAF chair David King.

"The difficulty we grappled with is how to do something different in this space when everybody is doing something else? There are a lot of overlaps and conflicting messages but also a lot of gaps to fill," he explained. "We do it by not reinventing the wheel – we recognise that everyone has a message but we can coordinate that across the industry to make a difference."

On such example is the coordination work the ISAF is undertaking to ensure a new resources portal from InfoSecurity Europe, christened the InfoSecurity Advisor and due to launch in April, doesn't overlap with existing sites like Get Safe Online.

Other forthcoming deliverables from the new organisation include a public awareness raising campaign to coincide with the InfoSecurity Europe event in April, as well as a new security guide for directors detailing what measures they need to take to protect their organisations.

The guide could raise the issue of information security prominently among parliamentarians too, argued Philip Virgo of the European Information Society Group (Eurim).

"If it puts the issues in a business context that could be very powerful in getting action at a political and corporate level," he added. "If the guide shows external good practice it [could become] a yardstick to hold up in parliament."

Chris Potter, a partner at PricewaterhouseCoopers who leads the annual Information Security Breaches survey, said that the ISAF could play an important part in helping those organisations that have been successful in improving security awareness share their best practice with others.

"There has been an enormous amount of learning and progress among the leading [organisations] which has been a challenge because … information security awareness is not really about awareness but changing behaviour, which is very hard," he added.

Kim Camman of mobile device encryption firm SafeBoot welcomed the initiative but said businesses and government organisations must also fulfill their responsibilities to educate users.

“Organisations have often relied on blanket emails to implement security awareness initiatives. However, we have all been guilty of deleting that ‘internal email from corporate IT’," Camman added. "It should be obvious by now that this communications method alone falls short of changing behaviours surrounding data security."

Tags:

reader comments

related articles

 

Infosec 2009: Experts discuss the cyber crime landscape

Users, companies, governments and police have to work together 28 Apr 2009

Personal data code aims to avoid security breaches

BCS and ISAF launch Personal Data Guardianship Code to change firms' personal data handling procedures 01 Jun 2009

related whitepapers

today's top stories

Best practice: Five steps to achieving your e-commerce goals

Brian Walker of Forrester Research gives his top tips for ensuring e-commerce success 06 Jul 2009

Google meets the NHS? Politicians show their IT naivety again

The Tories like technology. They increasingly seem to think IT is going to help them win the General Election due next year.... 06 Jul 2009

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

Reaching the email zero count

I have noticed something quite bizarre today. Both my inboxes (work and personal) are empty – somehow I have managed to work... 06 Jul 2009

Habitat gets a web site makeover

The furniture retailer is revamping its online presence to provide a fully transactional web site. CIO Jacques Dekock explains why 02 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Phil PavittAnalysis

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

UPS worker making a deliveryAnalysis

Global standardisation delivers benefits at UPS

Delivery giant sees benefits of central IT solution 02 Jul 2009

Advertisement

Primary Navigation