Human factor essential for IT security

People and processes more important than technology

Written by Robert Jaques

Global enterprises need to focus more time on policies, processes and people rather than technology if they are to successfully secure IT infrastructures, a report claimed today.

A poll of more than 4,000 information security professionals in more than 100 countries, carried out by IDC on behalf of the International Information Systems Security Certification Consortium (ISC)2, found that organisations have traditionally overlooked the role of human behaviour in favour of trusting hardware and software to solve security problems.

However, survey respondents say organisations are now beginning to recognise that technology is an enabler, not the solution, for implementing and executing a sound security strategy.

The study also found that responsibility for executing a sound security strategy is being increasingly shared across the organisation, making board-level officers accountable as part of a well-defined and articulated risk management programme.

Continuing a trend identified in last year's study, responsibility for securing information assets is shifting from the chief information officer (CIO) into other areas of senior management and business, including chief executive officer, chief financial officer, chief risk officer and chief information security officer, as well as legal and compliance departments.

"For organisations to proactively secure and protect their infrastructure, information, financial and physical assets requires the unconditional commitment to security at the financial, management and operational levels," said Allan Carey, program manager at IDC who led the study.

"Security management will always require the proper balance between people, policies, processes and technology to effectively mitigate the risks associated with today's digitally connected business environment."

IDC analysed responses from 4,016 full-time information security professionals in more than 100 countries, with nearly 40 per cent employed by organisations with $1 billion or more in annual revenue. Respondents came from three major regions of the world: North, Central and South America (57.3 per cent), EMEA (Europe, Middle East, Africa) (22.8 per cent), and A-P (Asia-Pacific, including Japan) (19.5 per cent).

Based on the report, IDC estimates the number of information security professionals worldwide in 2006 to be 1.5 million, an 8.1 per cent increase over 2005. This figure is expected to increase to slightly more than two million by 2010.

During the past 12 months, 67 per cent of security practitioners believe their efforts were effective in influencing management and the business stakeholders to drive security awareness and responsibility to their organisations. Looking forward to 2007, 73 per cent believe that they will be able to drive change in their organisations.

Overall, organisations were found to be spending a greater percentage of their information security budgets on personnel and training in 2006 than in 2005. Firms are spending more than 41 per cent of their security budgets, on average, on personnel and training to staff projects and support post-deployment management.

"IDC believes that the security professionals who participated in this study are taking their message to the masses and acting as 'change agents' within their organisations to ensure information security is recognised for its positive contributions to the business, as opposed to the sunk cost it has been perceived to be in past years," Carey said.

"The message of people and processes being absolutely crucial to effective information security is finally starting to resonate with business leaders."

"Security breaches that have made headlines during the past year have been a result of human error, and this year's Global Information Security Workforce Study further validates the conventional wisdom long held by information security professionals that people are the critical component of an effective information security programme," added Ed Zeitler, CISSP, executive director, (ISC)2.

"The fact that professionals are being heard by the C-suite and security responsibility is being shared across the organisation demonstrates that the information security profession has arrived and is being valued as an indispensable business component."

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

 

related white papers

today's top stories

Copyright agreement draft leaked again

ACTA workings published after Washington DC negotiating round 07 Sep 2010

Lloyd's Of London takes Facebook to the board

Peter Hambling, CIO of Lloyd’s of London, the venerable insurer, has made Facebook a priority for customer communications that required board approval.... 07 Sep 2010

Genuinely intuitive technology is years away

If the aim of technology is to simplify our lives, then it has failed 07 Sep 2010

Samsung P580 business laptop review

Not the most attractive business machine, but it's robust and performs well 06 Sep 2010

NAO urged to investigate £550m NPfIT contract

MP suspects BT deal represents very poor value for money 06 Sep 2010

Advertisement

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

ShanghaiAnalysis

How tech companies can crack China

Having a good product will only get you so far, as Rachel Fielding explains 07 Sep 2010

HandshakeFeatures

The pros and cons of output-based contracting

Proponents of output-based contracting say it enables more efficient service delivery, innovation and an improved customer experience. But it needs to be approached with care 07 Sep 2010

Primary Navigation