isse 2008 information security status

15
Information Security Status in Organisations 2008 Anas Tawileh, Jeremy Hilton, Stephen McIntosh Cardiff University

Upload: anas-tawileh

Post on 20-May-2015

482 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: ISSE 2008 Information Security Status

Information Security Status in Organisations

2008

Anas Tawileh, Jeremy Hilton, Stephen McIntosh

Cardiff University

Page 2: ISSE 2008 Information Security Status

Outline• Methodology and Approach

• Survey Findings

• Feedback

• Summary and Discussion

Page 3: ISSE 2008 Information Security Status

Methodology and Approach• Structured approach to questionnaire design

• Based on the Information Assurance Model

• Model describes a desirable state of information assurance in organisations

• Open-ended question added to elicit feedback

Page 4: ISSE 2008 Information Security Status

Respondents’ Profile

Page 5: ISSE 2008 Information Security Status

Respondents’ Profile

Page 6: ISSE 2008 Information Security Status

Organisation Sector

Page 7: ISSE 2008 Information Security Status

Information Security Requirements

Page 8: ISSE 2008 Information Security Status

Data Backup

Page 9: ISSE 2008 Information Security Status

Privacy and Integrity

Page 10: ISSE 2008 Information Security Status

Measures Against Internal Misuse

Page 11: ISSE 2008 Information Security Status

Respondents’ Feedback

“My goals as IT supervisor and management goals are not always the same, management is worried about sales/profits, and not security.”

“It would be nice to know how many "no's" one selected out all questions to slam it in the face of those opposing any IT security.”

Page 12: ISSE 2008 Information Security Status

Respondents’ Feedback

“I am concerned. I am the one and only who is concerned. After hours, anyone who somehow got admitted into our offices could walk out with a laptop sitting on the reception desk containing practically all the confidential info we have. Refusal to invest in a steel cable.”

Page 13: ISSE 2008 Information Security Status

Summary and Discussion• A significant gap exists between large

organisations and their smaller counterparts in the adoption of information security

• Organisations seem to focus more on confidentiality and authentication

• Privacy (still) is a growing concern

Page 14: ISSE 2008 Information Security Status

Summary and Discussion• Organisations are not very well prepared to

satisfy the requirement for external collaboration

• Over-reliance on technical measures

• Little attention is paid to the human aspect of security

Page 15: ISSE 2008 Information Security Status

Thank You.