SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Project Management

Is IT to blame for security woes?

Is IT to blame for security woes?

By:  Mark Hall  On: 22 Nov 2006 For: ComputerWorld (US) Creator

IT professionals polled in a recent survey had an "unflattering" view of if their colleagues or managers. IT leaders don't much care about the end-user shenanigans, those polled claimed.

Surveys single out IT for blame... ... in a growing security crisis. If you oversee mobile, remote or wireless-based workers, odds are pretty good that a fair portion of them are engaging in risky systems behavior, according to one recent poll. Another scary survey found that IT leaders don't much care about the end-user shenanigans -- or at least aren't doing much about them. John N. Stewart, chief security officer at Cisco Systems Inc., hopes the results of a survey conducted last summer for the networking vendor will light a fire under IT and prompt improvements in remote security. But the results themselves may undermine those hopes. The poll involved 1,000 remote users and 1,000 IT professionals. Although 68 percent of the users claimed to be "more cognizant of security concerns" when working outside the office, 24 percent still open e-mail from unknown sources, 5 percent continue to open attachments in such messages, 45 percent download business files to their home PCs, and nearly one-fifth let others use their work machines. Worse, Stewart says, many of the users had an "unflattering" view of IT: 57 percent said their direct managers -- not people in IT -- should govern their remote computing habits. Actually, that might be a good thing, given the results of a study completed last quarter by the BPM Forum. You see, the poll of 680 IT execs at the director level or higher reveals that at a stunning 40 percent of their companies, IT doesn't have "anything in place to handle security and compliance for mobile devices," says Adriano Gonzalez, vice president of strategy and programming at the business process management trade association. And 70 percent of those respondents don't plan to change their ways, he notes. Gonzalez says he was "astounded" by those figures and concludes that "we don't have the adequate tools, processes and frameworks for controls around mobility." Stewart, however, remains optimistic. For example, he says IT can exploit the preference of end users for taking direction on security from their bosses by helping managers craft programs that reward good security practices. Gonzalez is less sanguine. He sees finger-pointing everywhere, with most of the digits aimed at IT. And he says that making security successful for remote workers will "require a cultural transformation."

It will be a snap to build mobile apps...... that are easy to use and secure. Next year, that is. By mid-2007, SnapIn Software Inc. plans to deliver a mobile development and deployment environment that it claims will enable IT departments to create user-friendly and secure programs for smart phones, PDAs and other handhelds. Tom Trinner, vice president of product management and marketing at SnapIn, says that thus far, the company's software has been used in eight field trials by wireless carriers around the globe. Although SnapIn will sell the software primarily to telecommunications companies, there will be an enterprise version for IT users, he says. In addition to using the technology to guide end users through business apps, IT can have SnapIn automatically check handhelds to ensure that they're properly configured before loading a business program or accessing a Web site. Trinner quips that SnapIn also can apply the "ping of death" to a lost or stolen device to erase all data and render the device useless.


Sign up for our Newsletters
Tags: Mobile












Print |  Views: 735   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Mark Hall Mark Hall is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Security group releases business-relevant metrics
Security group releases business-relevant metricsThe Center for Internet Security will make its metrics available as a community resource and will include ways of measuring vulnerability assessments and time to recover from security incidents. How you can use these metrics to improve your company’s security
Mobile workers still struggling with security
Mobile workers still struggling with securityA fair amount of business users remain oblivious or unconcerned about many of the security issues involved with mobile devices, according to a new study published by Cisco and the National Cyber Security Alliance.
Half of UK financial firms not ready for compliance
Half of UK financial firms not ready for complianceMore than half (51 per cent) of all U.K. firms have not implemented the security processes to comply with legislative directives such as PCI and MiFID, says a report.
Trusting the trusted data centre
in a recent conversation with hewlett-packard co.’s chief technology officer, victor garcia, i first heard the concept of “trusted cloud computing”. coined by hp, the phrase characterizes what the company envisions as th
Dan Swanson's Security Resources: #12
business is about change, and peter’s change management repository is one of the very best, and certainly well worth regular visits by busy professionals.
Dan Swanson: Compliance, fraud, and business continuity
today’s information security professionals need to study current and upcoming regulatory compliance requirements to get ahead of the curve. we also need to help protect the organization from fraud and waste and of course that next disaster. this week’s resources involve
blog comments powered by Disqus