« Responding to the Growing Complexity in IT and Security | Main | Consolidation or Proliferation? The Future of Security Products »

The Importance of Security Surveys

I’ve just been checking out the new Symantec IT Risk Management Report. It’s the result of a year-long study based on interviews with IT executives and professionals around the world. Such surveys are mandatory reading for security managers as they can provide a valuable insight into trends and provide useful collateral evidence for business cases.

So what does this report tell us? Unfortunately, like too many of these surveys, there’s not much that’s of practical use to a CISO. Highlights include unsurprising findings such as the following.

“IT professionals rate themselves more effective in their deployments of technology than of process controls.”

“More-effective organizations – even though they often face higher risk levels – expect fewer incidents than less-effective organizations”.

“Best-in-class organizations perform with high effectiveness across most controls.”

“Differing internal viewpoints on IT Risk, and poor alignment between IT Risk Management programs and overall business objectives, may themselves create risk.”

Poor organizational support for IT Risk awareness and training is both a compelling example of poor alignment, and a major cause.”

“Best-in-class IT Risk management requires a disciplined approach…across people, process, and technology.”

As Basil Fawlty once put it: “Can’t we get you on Mastermind…specialist subject: stating the bleeding obvious…”

TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/4418

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on February 17, 2007 10:42 AM.

The previous post in this blog was Responding to the Growing Complexity in IT and Security .

The next post in this blog is Consolidation or Proliferation? The Future of Security Products.

Many more can be found on the main index page or by looking through the archives.