Archive for June, 2010

Over 1,000 Data Breaches in the UK

Thursday, June 24th, 2010

The Information Commissioner’s Office (ICO) has received over 1,000 reports of data breaches or losses since it was set up, and has issued a stern reminder that organisations must ensure that data is well protected. The biggest culprit is the NHS. The ICO’s Security Breaches Report shows the breakdown of breaches.

As we’ve said on our website (Data Protect Act Penalties), sooner or later the ICO will start levying fines for egregious breaches of the DPA – it would make sense to get one’s DPA compliance house in order before that happens, wouldn’t it? Simply buying and using the tools in our DPA Compliance Toolkit would prepare most organisations to face the worst!

ISO27001 – the Information Security Framework of the future

Wednesday, June 23rd, 2010

I agree entirely with John Verry’s description of today’s drivers for the adoption of ISO27001, which we expect to become more widely adopted over the next 15 years than ISO9001 is today (there are currently about 1 Million ISO9001 certifications worldwide).

“Driven to ISO 27001 … Driven by ISO 27001″ – presented by John Verry, principal consultant at Pivot Point Security (Hamilton, NJ) to the Unisys Community of Practice Group on June 15, 2010, focuses on three “pain” points driving organizations to the ISO-27001 framework as a simple and logical response. Verry cites the “cloud economy”, a “flatter world” and the growth of increasingly ambiguous and overlapping information security regulations as the main factors – and then explores how and why ISO 27001 is poised to change information security.

We’ve been working on ISO27001 since its inception and our unique, and uniquely comprehensive and integrated range of ISO27001 books, tools and resources is designed to help organisations around the world use this standard in their businesses – drawing on advice, tools, guidance, training or consultancy as required.

Selling Information Security to the Board

Tuesday, June 22nd, 2010

I’ve always believed that board support is essential for information security management projects to succeed across a business. I’ve also always recognised that not all security professionals naturally have the sales skills that are necessary to successfully pitch information security initiatives to boards of directors many of whom, themselves, combine sales skills with quite short attention spans. I originally wrote The Case  for ISO27001 to provide, in one place, the wide range of arguments that could be made in favour of an organisation adopting ISO27001 as the standard for its information security management system.

I’ve just written another book, Selling Information Security to the  Board, as a primer for those interested in developing their sales skills. The book originated in a presentation, Infosecurity As A Mindset: Selling IT To The Board, that I did at Infosec 2010 on exactly the same subject, and is (I hope) the first in a small collection of books and other products that are designed to expand the range of support available to IT professionals who, as part of their role, have to get management buy-in to an IT or information security project.

Top 5 Social Media Risks for Organisations

Wednesday, June 9th, 2010

ISACA has, apparently, published research that identifies the 5 top social media risks faced by organisations today. I’ve said, previously, that organisations should embrace social media as part of their marketing and communications strategy, and that a governance approach to social media is necessary. The IT Governance social media governance toolkit is, of course, specifically designed to give organisations all the tools that they might need to govern this area effectively – and includes detailed user guidance for all the key areas of social media activity that might be important.