<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Alan Calder on IT Governance, information security &#38; ISO 27001</title>
	<atom:link href="http://www.alancalderitgovernanceblog.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.alancalderitgovernanceblog.com</link>
	<description>Alan Calder, author of "IT Governance: a Manager's Guide to Information Security and ISO27001/ISO27002", talks about current governance and information security issues.</description>
	<lastBuildDate>Wed, 07 Dec 2011 14:41:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>EU Commission and UK Cyber Security Strategy</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/12/eu-commission-and-uk-cyber-security-strategy/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/12/eu-commission-and-uk-cyber-security-strategy/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 13:24:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Business and the Economy]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO 27002 (ISO 17999)]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[White Collar Crime]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=811</guid>
		<description><![CDATA[While the UK cyber security strategy, published last week, is full of good stuff, it is lacking in one key area: compulsion. My view on this was quite widely reported last week: if UK organisations won&#8217;t take adequate action to protect personal data, under legislation that has been around since 1998, and won&#8217;t report breaches voluntarily [...]]]></description>
			<content:encoded><![CDATA[<p>While the UK cyber security strategy, published last week, is full of good stuff, it is lacking in one key area: compulsion. My view on this was quite widely reported last week: if UK organisations won&#8217;t take adequate action to protect personal data, under legislation that has been around since 1998, and won&#8217;t report breaches voluntarily to the Information Commissioner, then what on earth is going to cause them to share information about much more damaging cyber breaches?</p>
<p>The threat of a £500k fine hasn&#8217;t led to a dramatic increase in the number of UK organisations reporting data breaches, but nor has there been a dramatic decline in the number of successful hack attacks reported &#8211; initially, usually by the hackers, not by the hacked.</p>
<p>The European Commission appears to understand that organisations, public and private, are not pre-disposed to protect personal data. The <a href="http://www.ft.com/cms/s/2/bf962998-1d01-11e1-a26a-00144feabdc0.html">proposed revisions to the European Data Protection Directive </a>should, if enacted as currently drafted, bring substantial change &#8211; the threat of a fine equivalent to 5% of global revenue (applicable to EU entities, including EU subsidiaries of foreign companies) should bring a substantial change to data protection behaviour. Allied to a legal requirement to report breaches within 24 hours, this regulatory imperative may finally bring real protection to individual data.</p>
<p>Now, imagine how quickly UK organisations would get their cyber security houses in order if they were faced with a requirement to report all breaches within 24 hours and faced a very substantial fine &#8211; on top of the losses and other penalties they incurred. And imagine how quickly cyber security would find its way onto the corporate governance agenda and onto the list of issues about which shareholders are concerned.</p>
<p>It will be interesting to watch the progress of the EU directive and, alongside it, progress in implementing the UK&#8217;s current cyber security strategy. I hope there will be progress in both and fear that both may ultimately be ineffective &#8211; the EU law because the compulsion element is watered down, and the UK strategy because it is already quite watery.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/12/eu-commission-and-uk-cyber-security-strategy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What to do about UK data breaches?</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/11/what-to-do-about-uk-data-breaches/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/11/what-to-do-about-uk-data-breaches/#comments</comments>
		<pubDate>Thu, 24 Nov 2011 10:01:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Mobile Devices]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=807</guid>
		<description><![CDATA[Another day, another (damning) survey. A recent report from Big Brother Watch &#8220;uncovered more than 1000 incidents across 132 local authorities, including at least 35 councils who have lost information about children and those in care. Highly confidential information has been treated without the proper care and respect it deserves. At least 244 laptops and [...]]]></description>
			<content:encoded><![CDATA[<p>Another day, another (damning) survey.</p>
<p>A recent <a href="http://www.bigbrotherwatch.org.uk/home/2011/11/local-authority-data-loss-exposed.html">report from Big Brother Watch </a><em>&#8220;uncovered more than 1000 incidents across 132 local authorities, including at least 35 councils who have lost information about children and those in care.<br />
Highly confidential information has been treated without the proper care and respect it deserves. At least <strong>244 laptops</strong> and portable computers were lost, while a minimum of <strong>98 memory sticks</strong> and more than <strong>93 mobile devices</strong> went missing.<br />
Yet of the <strong>1035 incidents</strong>, local authorities reported that just <strong>55 were reported</strong> to the Information Commissioner’s Office. Perhaps more concerning, just 9 incidents resulted in termination of employment.&#8221;</em></p>
<p>This survey is just the latest in a long series of reports and news releases that all point at the same three inadequacies: </p>
<ul>
<li><a href="http://www.bbc.co.uk/news/uk-england-leicestershire-15858562">Leicestershire City Council</a> lost an unencrypted USB stick containing personal information of 80 children;</li>
<li>a <a href="http://www.scl.org/site.aspx?i=ne23563">Scottish advocate whose unencrypted laptop </a>(containing personal data of individuals involved in cases she was working on) was stolen while she was on holiday;</li>
<li>An <a href="http://www.ico.gov.uk/news/latest_news/2011/laptop-thefts-highlight-the-need-for-encryption-05102011.aspx">ASCL employee </a>had a laptop containing unencrypted personal data stolen from home;</li>
<li><a href="http://www.ico.gov.uk/news/latest_news/2011/laptop-thefts-highlight-the-need-for-encryption-05102011.aspx">Holly Park School in London </a>had an unencrypted laptop stolen from an unlocked office at the school;</li>
<li><a href="http://www.ico.gov.uk/news/latest_news/2011/thousands_of_tenants_details_found_on_memory_stick_left_in_pub_04082011.aspx">Two London Housing Associations </a>allowed details of thousands of their tenants to find their way onto an unencrypted USB stick belonging to one of their contractors &#8211; which was then left in a pub!;</li>
<li><a href="http://www.ico.gov.uk/news/latest_news/2011/council-warned-after-personal-data-was-missing-for-two-years-21112011.aspx">Southwark council &#8216;misplaced&#8217; </a>- for two years &#8211; an unencrypted laptop containing the personal information of 7,200 people &#8211; which was then found on a skip;</li>
<li>A survey revealed that <a href="http://www.scmagazineuk.com/number-of-usb-sticks-left-in-dry-cleaners-continues-to-rise/article/197274/">17,000 USB sticks </a>were left in dry cleaners during 2010!</li>
</ul>
<p>The list goes on &#8211; as I identified yesterday, nearly 50% of breaches reported to the ICO elate to lost, unencrypted laptops or USB sticks. And it appears that the number of (so far) unreported losses may exceed those reported.</p>
<p>And the position on encrypting laptops and USB sticks is clear. According to the ICO&#8217;s <a href="http://www.ico.gov.uk/news/latest_news/2011/laptop-thefts-highlight-the-need-for-encryption-05102011.aspx">Acting Head of Enforcement, Sally Anne Poole</a>:</p>
<p>“The ICO’s guidance is clear: all personal information – the loss of which is liable to cause individuals damage and distress &#8211; must be encrypted. This is one of the most basic security measures and is not expensive to put in place &#8211; yet we continue to see incidents being reported to us. This type of breach is inexcusable and is putting people’s personal information at risk unnecessarily.&#8221;</p>
<p>There are three things that every organisation must do as a matter of course:</p>
<ol>
<li>Ensure that all laptops &#8211; or at least all laptops that might at some point contain personal information &#8211; have boot-level, FIPS 140-2 encryption software installed;</li>
<li>Ensure that all USB sticks that come onto corporate premises, or which are used by staff and contractors, are also encrypted to FIPS 140-2;</li>
<li>Ensure that all staff &#8211; managers as well as front line staff &#8211; have adequate training and awareness around their responsibilities for protecting personal data.</li>
</ol>
<p>Any organisation can do these three things. It isn&#8217;t hard.</p>
<p>My own company has tried to make it easy for our customers. We&#8217;ve provided specific <a href="http://www.itgovernance.co.uk/products/2957">DPA classroom training</a> as well as a comprehensive <a href="http://www.itgovernance.co.uk/products/1788">DPA Compliance Documentation Toolkit</a> for some years.</p>
<p>We&#8217;ve now gone a step further, and identified appropriate <a href="http://www.itgovernance.co.uk/encryption-dpa.aspx">laptop encryption software</a>, as well as appropriate <a href="http://www.itgovernance.co.uk/products/3657">CESG-approved encrypted USB sticks</a>, and we&#8217;re supplying both &#8211; in single units or in bulk &#8211; directly from our UK website and service centre. We&#8217;ve also developed a unique<a href="http://www.itgovernance.co.uk/products/3392"> DPA e-Learning Staff Awareness </a>course that can be deployed across the largest organisation and which will ensure (with necessary evidence) that staff have received the core awareness training they need.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/11/what-to-do-about-uk-data-breaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Norfolk &#8211; a hotbed of DPA breaches</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/11/norfolk-a-hotbed-of-dpa-breaches/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/11/norfolk-a-hotbed-of-dpa-breaches/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 08:41:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=787</guid>
		<description><![CDATA[Norfolk, according to a recent article, is a hotbed of Data Protection Act breaches: with multiple incidents &#8211; more than 150 since 2008, apparently &#8211; at Norfolk County Council, at regional hospitals and the police force. With breaches ranging from misuse of privileged access to personal information to real negligence &#8211; a child protection report that [...]]]></description>
			<content:encoded><![CDATA[<p>Norfolk, according to <a href="http://www.edp24.co.uk/news/politics/staff_sacked_after_security_breaches_at_police_and_councils_in_norfolk_1_1133024">a recent article</a>, is a hotbed of Data Protection Act breaches: with multiple incidents &#8211; more than 150 since 2008, apparently &#8211; at Norfolk County Council, at regional hospitals and the police force. With breaches ranging from misuse of privileged access to personal information to real negligence &#8211; a child protection report that was hand-delivered to the wrong address &#8211; the picture that emerges is one of a county in which there is widespread failure to understand the requirements of the DPA, where errors and abuse go hand-in-hand, and the security of personal data appears to depend more on luck than on a systematic, organised approach to its protection.</p>
<p>Isn&#8217;t it remarkable that, nearly 14 years since the passage of the DPA, and in spite of the Information Commissioner having the power to levy pretty significant fines, there should be such a pervasive disregard of the basic principles of protecting personal data?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/11/norfolk-a-hotbed-of-dpa-breaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analysis of Information Commissioner Cases</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/11/analysis-of-information-commissioner-cases/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/11/analysis-of-information-commissioner-cases/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 09:22:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Business and the Economy]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO 27002 (ISO 17999)]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Mobile Devices]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=784</guid>
		<description><![CDATA[We carried out an analysis of the data breach cases which led to the UK&#8217;s Information Commissioner extracting an undertaking from the organisation concerned. Over the last 18 months (May 2010 &#8211; mid-November 2011), this is the breakdown of 85 cases: Incident type No. Cases % Lost / stolen unencrypted laptop 16 18.8% Lost / [...]]]></description>
			<content:encoded><![CDATA[<p>We carried out an analysis of the data breach cases which led to the UK&#8217;s Information Commissioner extracting an undertaking from the organisation concerned. Over the last 18 months (May 2010 &#8211; mid-November 2011), this is the breakdown of 85 cases:</p>
<table width="500px" border="0" cellspacing="0" cellpadding="0">
<tr>
<td valign="bottom" nowrap="nowrap" width="80%"><strong>Incident type</strong></td>
<td valign="bottom" nowrap="nowrap" width="10%"><strong>No. Cases</strong></td>
<td valign="bottom" nowrap="nowrap" width="10%">
<p style="text-align: right;"><strong>%</strong></p>
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Lost / stolen <em><strong>unencrypted</strong></em> laptop</td>
<td valign="bottom" nowrap="nowrap" width="10%">
16
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
18.8%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Lost / stolen <em><strong>unencrypted</strong></em> USB (20) CD (1) camcorder (1)</td>
<td valign="bottom" nowrap="nowrap" width="10%">
22
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
25.9%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Lost / binned / theft / exposure of papers records</td>
<td valign="bottom" nowrap="nowrap" width="10%">
24
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
28.2%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Data exposed on website / emailed or<br /> faxed to unauthorised individuals</td>
<td valign="bottom" nowrap="nowrap" width="10%">
16
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
18.8%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Unsecure / incorrect / exposure of electronic data storage</td>
<td valign="bottom" nowrap="nowrap" width="10">
7
</td>
<td valign="bottom" nowrap="nowrap" width="10">
8.3%
</td>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Unsecure / incorrect / exposure of electronic data storage</td>
<td valign="bottom" nowrap="nowrap" width="10">
7
</td>
<td valign="bottom" nowrap="nowrap" width="10">
8.3%
</td>
</tr>
</tbody>
</table>
<p>The largest category of data breaches is to do with <strong>paper records</strong>, not with digital data. Many people don&#8217;t seem to think that that DPA also applies to paper records. More than that, it is harder for organisations to impose technical security controls on paper documents. This gap can only be filled by training. In today&#8217;s climate, the most cost-effective way to train people is <a href="http://www.itgovernance.co.uk/products/3392">DPA Staff Awareness eLearning </a>- this ensures that all staff get a consistent message, tests staff understanding of the key concepts, retains records of completion of training and testing, and enables the employer to systematically train everyone at a low individual cost.</p>
<p>Nearly 50% of the cases are due to an absence of encryption &#8211; either of a laptop or of a USB stick. Failure to require staff to use <a href="http://www.itgovernance.co.uk/products/3657">encrypted USB stick (SafeSticks</a>) s is, bluntly, reckless.</p>
<p>The breakdown of organisations concerned is also interesting:</p>
<table width="500px" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%"><strong>Offender</strong><strong></strong></td>
<td valign="bottom" nowrap="nowrap" width="10%"><strong>No. Cases</strong><strong></strong></td>
<td valign="bottom" nowrap="nowrap" width="10%">
<p style="text-align: right;"><strong>%</strong><strong></strong></p>
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Lawyers</td>
<td valign="bottom" nowrap="nowrap" width="10%">
4
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
4.7%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Schools</td>
<td valign="bottom" nowrap="nowrap" width="10%">
11
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
12.9%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Councils</td>
<td valign="bottom" nowrap="nowrap" width="10%">
18
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
21.2%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Social services</td>
<td valign="bottom" nowrap="nowrap" width="10%">
4
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
4.7%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Hospitals / NHS trusts</td>
<td valign="bottom" nowrap="nowrap" width="10%">
29
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
34.1%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Commercial organisations</td>
<td valign="bottom" nowrap="nowrap" width="10%">
10
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
11.8%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Police</td>
<td valign="bottom" nowrap="nowrap" width="10%">
3
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
3.5%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Government</td>
<td valign="bottom" nowrap="nowrap" width="10%">
6
</td>
<td valign="bottom" nowrap="nowrap" width="10%">
7.1%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%"> </td>
<td valign="bottom" nowrap="nowrap" width="10%"> </td>
<td valign="bottom" nowrap="nowrap" width="10%"> </td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Public sector</td>
<td valign="bottom" nowrap="nowrap" width="10%"> </td>
<td valign="bottom" nowrap="nowrap" width="10%">
88.2%
</td>
</tr>
<tr>
<td valign="bottom" nowrap="nowrap" width="80%">Private sector</td>
<td valign="bottom" nowrap="nowrap" width="10%"> </td>
<td valign="bottom" nowrap="nowrap" width="10%">
11.8%
</td>
</tr>
</tbody>
</table>
<p>I&#8217;m convinced that the only reason the private sector does so well in these statistics is the anomaly that the public sector is required to report data breaches, but the private sector is not (yet). This may change a bit with the new PECR requirement on ISPs to report data breaches but, until the appearance of a broader pan-european data breach reporting requirement, I would expect this reporting imbalance to continue.</p>
<p>The private sector is, however, subject to potentially hefty financial penalties &#8211; from the ICO and from individual regulatory bodies, such as the FSA. More importantly, breached private sector organisatons are subject to those most severe of business penalties &#8211; reputation destruction and customer desertion. The sensible private sector organisation will be taking steps, now that <a href="http://www.itgovernance.co.uk/products/3577">ISO27035</a> has been published, to ensure that its incident management and <a href="http://www.itgovernance.co.uk/products/3669">security breach </a>reporting capabilities are up to scratch.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/11/analysis-of-information-commissioner-cases/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SMEs are also Cyber Prey</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/11/smes-are-also-cyber-prey/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/11/smes-are-also-cyber-prey/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 08:30:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO 27002 (ISO 17999)]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=782</guid>
		<description><![CDATA[It&#8217;s encouraging to see that a growing number of SMBs (small and medium businesses) are getting wise to the fact that they are as much at risk in cyber space as are larger organisations like Sony. More and more of our clients are asking us to carry out penetration testing projects on their networks and websites. I hope they [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s encouraging to see that a growing number of SMBs (small and medium businesses) are getting wise to the fact that they are as much at risk in cyber space as are larger organisations like Sony. More and more of our clients are asking us to carry out <a href="http://www.itgovernance.co.uk/penetration-testing-packages.aspx">penetration testing projects </a>on their networks and websites. I hope they are in the vanguard and that penetration testing becomes as standard a cyber defence tool as strong passwords.</p>
<p>There are a number of reasons why SMBs are increasingly hunted as cyber prey:</p>
<ol>
<li>Their cyber defences are usually inadequate &#8211; poorly written web applications, loopholes in their network defences, out-of-date patching, default security configurations, and so on;</li>
<li>SMBs also have valuable information &#8211; credit card data, personal information, intellectual property, and so on &#8211; and stealing an aggregate 10,000 records from 100 SMBs is likely to be easier than a single theft of 10,000 records from a larger, better defended organisation;</li>
<li>Infecting hundreds of SMB websites with malware is an inexpensive way of creating pharming sites, or Trojan downloader sites, which have the added advantage of legitimate URLs;</li>
<li>Controlling hundreds of SMB network servers in an SMB &#8216;bot net&#8217; can be more effective for a hacker than controlling 1,000s of domestic PCs.</li>
</ol>
<p>The cost of recovery from a successful cyber attack can be significant; the damage done to clients and credibility can be even more significant. Most smaller organisations shy away from penetration testing because it seems arcane, technical and expensive. It doesn&#8217;t have to be.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/11/smes-are-also-cyber-prey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Increase infosec spending &#8211; reduce cyber damages</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/11/increase-infosec-spending-reduce-cyber-damages/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/11/increase-infosec-spending-reduce-cyber-damages/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 11:02:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Business and the Economy]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO 27002 (ISO 17999)]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=779</guid>
		<description><![CDATA[A recently published study into Global 2000 IT-spending intentions identified that 39% of corporations are spendng more on information security this year, with 37% planning to increase spending in 2012. With cyber security identified as a key strategic threat facing organisations worldwide, sensible CIOs and CISOs will now be spending at least 13% of their IT budget directly [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://www.marketwatch.com/story/spending-on-information-security-continues-to-outpace-the-rest-of-corporate-it-according-to-latest-bi-annual-study-of-the-global-2000-by-theinfopro-2011-11-17">recently published study </a>into Global 2000 IT-spending intentions identified that 39% of corporations are spendng more on information security this year, with 37% planning to increase spending in 2012.</p>
<p>With cyber security identified as a key strategic threat facing organisations worldwide, sensible CIOs and CISOs will now be spending at least 13% of their IT budget directly on information security. There is a growing body of evidence that points to increased expenditure having a direct impact on reducing frequency and impace of cyber crime. In particular, the 2010 Cyber Security Watch Survey found that there was, on average a 10% reduction in the losses from cybercrime resulting from significantly increasing spend on cyber security. As individual cyber incidents can cost $3 million or more, a 10% reduction can be seriously worth having!</p>
<p>In fact, adopting and applying <a href="http://www.itgovernance.co.uk/cybersecurity-standards.aspx">cyber security standards </a>for managing information security and business resilience can pay off massively &#8211; depending on whether you adopt a self-help approach or bring in<a href="http://www.itgovernance.co.uk/consulting.aspx"> outside consultants</a>, a best practice ISO27001 Information Security Management System can cost as little as £3.5k to £10k to implement and more than pay for itself in reduced financial damages in almost  no time!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/11/increase-infosec-spending-reduce-cyber-damages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ITG 5 (IT Governance: a Manager&#8217;s Guide &#8211; 5th Edition) completed!</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/11/itg-5-it-governance-a-managers-guide-5th-edition-completed/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/11/itg-5-it-governance-a-managers-guide-5th-edition-completed/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 09:32:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Business and the Economy]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO 27002 (ISO 17999)]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=766</guid>
		<description><![CDATA[At the end of October, we submitted the manuscript of the 5th Edition of our best-selling book on implementing an ISO27001 Information Security Management System (ISMS) to our external publisher, Kogan Page. It should be in bookshops across the world in Spring 2012. This 5th Edition is completely updated and combines the content of International IT Governance, the [...]]]></description>
			<content:encoded><![CDATA[<p>At the end of October, we submitted the manuscript of the 5th Edition of our best-selling book on implementing an ISO27001 Information Security Management System (ISMS) to our external publisher, Kogan Page. It should be in bookshops across the world in Spring 2012.</p>
<p>This 5th Edition is completely updated and combines the content of International IT Governance, the version of the book that we produced for the North American market, with that of IT Governance. This means that there will now be a single edition, with coverage of IT governance, legal, security and compliance issues in the UK and in North America, as well as in Europe and elsewhere across the world.</p>
<p>We&#8217;ve obviously also updated all the technology content of the book, and have included the most recent information about <a href="http://www.itgovernance.co.uk/Advanced-Persistent-Threats-APT.aspx">Advanced Persistent Threats</a>, attack vectors, <a href="http://www.itgovernance.co.uk/cybersecurity-standards.aspx">cyber crime standards</a>, the cyber resilience agenda, <a href="http://www.itgovernance.co.uk/social-media-governance.aspx">social media governance</a>, <a href="http://www.itgovernance.co.uk/pci_dss.aspx">PCI DSS</a> and, of course, <a href="http://www.itgovernance.co.uk/cloud-computing.aspx">cloud computing</a>.  </p>
<p>While the core standards, ISO/IEC 27001 and ISO/IEC 27002, have not yet been updated from the versions published in 2005, a whole family of <a href="http://www.itgovernance.co.uk/iso27000-family.aspx">ISO27000 standards</a> has been created and are being published with great regularity.  Our new book incorporates material from a number of these standards and places them in their broader implementation context.</p>
<p>While working on the book, I came across a growing number of surveys and reports in which the link between increased expenditure on information security and a reduced incidence of cyber breaches (and, therefore, reduced financial and business impairment) is clear.  It has always been obvious to us that, in an insecure neighbourhood &#8211; and the Internet is a deeply insecure environment &#8211; it is simply good sense to lock the doors, alarm the house and secure one&#8217;s valuable assets.</p>
<p>The growing number of organisations certificated to ISO27001 (many of whom have taken advantage of our range of <a href="http://www.itgovernance.co.uk/iso27001_training.aspx">certificated ISO27001 training </a>courses to prepare themselves) all contribute to greater information security awareness amongst users of digital assets. We hope that the 5th edition of IT Governance: a Manager&#8217;s Guide will help many more organisations around the world make the first step toward better digital self-preservation.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/11/itg-5-it-governance-a-managers-guide-5th-edition-completed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>COBIT 5 Exposure Draft</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/06/cobit-5-exposure-draft/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/06/cobit-5-exposure-draft/#comments</comments>
		<pubDate>Tue, 28 Jun 2011 16:28:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[ITIL]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=763</guid>
		<description><![CDATA[COBIT 5 Exposure Draft is now available for public review &#8211; and will be available until 31 July. COBIT 5 is a huge piece of work - as thorough and as comprehensive as anything from ITGI. For those outside the development and review team, getting to grips with this draft will take some time. It is a very COBIT-focused framework [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.isaca.org/Knowledge-Center/Research/ResearchDeliverables/Pages/COBIT-5-Exposure-Draft.aspx">COBIT 5 Exposure Draft </a>is now available for public review &#8211; and will be available until 31 July. COBIT 5 is a huge piece of work - as thorough and as comprehensive as anything from ITGI. For those outside the development and review team, getting to grips with this draft will take some time.</p>
<p>It is a very COBIT-focused framework &#8211; COBIT as the solution to everything. It would be useful for the framework to have included more work on integration with other widely-implemented standards and frameworks like ITIL and ISO27001 &#8211; and, while there is a solid definition of the difference between governance and management in COBIT 5, I didn&#8217;t see anything which specifically addressed the board-level issues which are (I think) so well dealt with in ISO/IEC 38500.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/06/cobit-5-exposure-draft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Does boredom mean security?</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/06/does-boredom-mean-security/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/06/does-boredom-mean-security/#comments</comments>
		<pubDate>Mon, 27 Jun 2011 16:36:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=761</guid>
		<description><![CDATA[Uh, no. A LulzSec member says the group is &#8216;bored&#8217; and is therefore disbanding. Does that mean an end to cyber attacks? Uh, no. The individual members of a group of hackers don&#8217;t all stop doing stuff just because a couple of the members are bored. Sure, they might disband. Some of them have &#8211; allegedly &#8211; already joined [...]]]></description>
			<content:encoded><![CDATA[<p>Uh, no. A LulzSec member says the <a href="http://www.businessweek.com/ap/financialnews/D9O3O1G00.htm">group is &#8216;bored&#8217; </a>and is therefore disbanding. Does that mean an end to cyber attacks? Uh, no. The individual members of a group of hackers don&#8217;t all stop doing stuff just because a couple of the members are bored. Sure, they might disband. Some of them have &#8211; allegedly &#8211; already joined up (again?) with Anonymous. Irrespective of what the ex-LulzSec folk do, they&#8217;ve already done enough to inspire copy-cat attackers around the world &#8211; or so says Kevin Mitnick, retired hacker, author and security consultant.</p>
<p>And, if that&#8217;s not enough, kids are being taught hacking basics at<a href="http://www.inquisitr.com/117407/defcon-kids-the-next-lulzsec-could-be-run-by-eight-year-olds/"> DEFCON kids </a>(for 8 to 13-year olds), so that takes care of hacking for the future. And, as I&#8217;ve said on many occasions in the past, it&#8217;s not just hackers doing it for the craic, there is a whole commercial hacking scene as well: for instance, a <a href="http://www.news.com.au/technology/hackers-for-hire-revealed-cyber-crims-paid-to-raid-private-emails/story-e6frfro0-1226081982431">cyber-spying company in India </a>specialises in hacking into email and stealing information contained therein.</p>
<p>The Internet is an extremely insecure environment. There are lots of bad people out there. It&#8217;s like medieval Europe &#8211; when bands of predatory attackers roamed around, looking for opportunities to rape, rob and pillage &#8211; and towns and cities threw up battlements and turrets, and dug moats, and installed portcullises and so on &#8211; all to keep the bad people out. If you decided to build your house on the plain, or to run a fair beside the river, you would very quickly lose everything. It&#8217;s like that on the Internet today. You can&#8217;t just connect to the Internet and expect to remain unpillaged for long &#8211; you need battlements and other such stuff. Today, we call that stuff Internet Security and, because we can&#8217;t check it by walking (or riding) around the walls just looking for cracks that a pillager might exploit, we use <a href="http://www.itgovernance.co.uk/penetration-testing.aspx">penetration testing</a> and <a href="http://www.itgovernance.co.uk/products/2593">vulnerability scanning</a> to make sure that we&#8217;ve identified and closed down any security holes BEFORE they are exploited.</p>
<p>It does tend to be cheaper to close vulnerabilities before they are exploited&#8230;..</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/06/does-boredom-mean-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pre-hack backups</title>
		<link>http://www.alancalderitgovernanceblog.com/2011/06/pre-hack-backups/</link>
		<comments>http://www.alancalderitgovernanceblog.com/2011/06/pre-hack-backups/#comments</comments>
		<pubDate>Fri, 24 Jun 2011 14:02:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[ISO 25999]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO 27002 (ISO 17999)]]></category>
		<category><![CDATA[IT Governance]]></category>

		<guid isPermaLink="false">http://www.alancalderitgovernanceblog.com/?p=759</guid>
		<description><![CDATA[Among the most common errors of judgement that I see from company directors is the failure to carry out regular and detailed reviews of their business continuity arrangements. For most boards, the whole discussion is boring. It becomes even more boring when the discussion has to work its way through identification of critical systems and processes, [...]]]></description>
			<content:encoded><![CDATA[<p>Among the most common errors of judgement that I see from company directors is the failure to carry out regular and detailed reviews of their business continuity arrangements. For most boards, the whole discussion is boring. It becomes even more boring when the discussion has to work its way through identification of critical systems and processes, determination of Minimum Tolerable Periods of Disruption and Recovery Time Objectives, as well as identifying threats and vulnerabilities and estimating likelihoods and impacts of external events that might unacceptably disrupt key processes.</p>
<p>Inactions have consequences. <a href="http://continuitycentral.com/news05803.html">DistributeIT.com.au ceased to exist as an independent business </a>because it hadn&#8217;t identified the possible impact of a devastating hack attack: it didn&#8217;t have adequate offsite backups for the 4,800 websites it hosted.  And that&#8217;s what business continuity plans are for: to ensure that, as an organisation, you can survive when something terrible happens. You would have thought that an IT company would understand the importance of backups but, again, my experience is that most organisations never actually think through the circumstances in which they might have to recover from their backups and they are therefore never prepared when disaster strikes.</p>
<p>The good news, of course, is that there are internationally recognised standards for business continuity management &#8211; <a href="http://www.itgovernance.co.uk/products/1364">BS25999</a> (shortly to be ISO22301) and <a href="http://www.itgovernance.co.uk/products/2213">ISO/IEC 27031 </a> - and there are <a href="http://www.itgovernance.co.uk/products/2203">Business Continuity Management Toolkits</a> to help you with an BCM implementation &#8211; but there is no substitute for directors paying attention to what is going on in the risk world around us, and taking appropriate action to survive the unexpected. Right now, of course, being hacked is one of the more likely things to happen - so there really isn&#8217;t an excuse for being caught napping on this one!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alancalderitgovernanceblog.com/2011/06/pre-hack-backups/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

