A recent study by Cisco has revealed that some countries do not take information security as seriously as one might expect. According to the article the awareness level is tied up with culture. Some corporations allow third-parties entrance into their facilities with no oversight of their activity once inside. Talking about corporate matters with family and strangers are also shockingly common in some nations. Personal use of computers is also present, presenting a security risk. Marie Hattar cites one interesting example: work mobile phones. A lot of companies give corporate cell phones to employees that are used around the clock, even when the employee is not at work. According to Hattar, combined with young workers, these are "completely blurring between what's personal and what's your work life." Another shocking detail is that a large amount of employees make settings changes that make their information less secure. According to the report, "[a] majority of IT professionals said employees accessing unauthorized websites and programs contributed to up to 25% of corporate data leakage. IT pros in the U.S., Brazil and India were the most likely to express this view." One important issue that needs to be considered is what to do about data shared between nations when the cultural security standards are different? How to companies address these situations?
Source articles:
http://news.cnet.com/8301-1009_3-10054314-83.html
http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1332760,00.html#
http://www.forbes.com/technology/2008/09/29/outsourcing-data-breaches-security-tech-cx_ag_0930outsource.html
Tuesday, September 30, 2008
Subscribe to:
Post Comments (Atom)
Data that a company uses but is stored in various locations around the world can not be considered safe. When cultural security standards are different the idea of malicious insiders becomes a huge problem. If a company's branch in one country has access to all the companies data but access to the data is unrestricted there, then the data is unrestricted anywhere across the network which is a huge concern. Companies only have 1 way to address these concerns and that is to implement a company wide security protocol that applies regardless of security standards in a given country. The security at the corporate hq in new york should be the same as some 3rd worl factory in new delhi. By implenting a solid company wide security structure data will be safe no matter what the cultural standards dictate.
ReplyDelete