Home > Security News > Security survey finds increase in security standards adoption
Security News:
EMAIL THIS

Security survey finds increase in security standards adoption

By Neil Roiter, Senior Technology Editor, Information Security magazine
30 Oct 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

News Analysis
Ernst & Young's 2008 Global Information Security Survey begs the eternal question, depending on how you look at the numbers: Is the glass half full or half empty?

Latest security surveys:

Security spending driven by mergers, Web 2.0 and compliance: PricewaterhouseCoopers' annual Global State of Information Security Survey found mergers, Web 2.0 and other business initiatives driving spending nearly as much as compliance.

Community banks to increase security spending, survey finds: Smaller banks place a priority on protecting customer data and plan to spend more on security technology, according to a new survey


Sophos sees increase in malicious email attachments: Spam using malicious attachments and social engineering techniques are targeting computer users in rising numbers, according to security vendor Sophos.

For example, the survey clearly shows that many companies may be slow to address growing security concerns, such as reliance on third parties -- partners, vendors and contractors. Only 45% of respondents include specific security requirements in all third-party contracts, but an optimist might say this reflects a trend in the right direction. One wonders if the other 55% write language into their more sensitive contracts that involve sharing confidential data or access to key systems.

The 11th annual survey by Ernst & Young (E&Y) polled nearly 1,400 organizations in more than 50 countries with annual revenues ranging from less than $100 million to more than $25 billion, as well as non-profits. Nearly a third of the organizations polled were in the financial services sector and 13% were in manufacturing, the second highest group.

The report comes on the heels of PricewaterhouseCoopers' annual Global State of Information Security Survey.

On a positive note, adoption of international information security standards is clearly trending up. Use of ISO/IEC 27001:2005 was up 15% over 2007 and ISO/IEC 27002:2005 rose 9% over 2007. The E&Y report stated that management standards, such as ISO 9000, have been adopted in certain industries where information security standards are becoming a necessity for doing business.

The survey also found that organizations are overwhelmingly planning to increase or maintain information security spending as a percentage of their total expenditures. The survey was conducted from June 6 to August 1, before the international economic crisis was in full bloom, so the question going forward is: What was the impact on total expenditures? It would be interesting to see the results if the survey was conducted now.

SearchSecurity radio:

Interestingly, 50% of the respondents said organizational awareness was the most significant challenge to information security initiatives, edging out availability of resources, budget and addressing new threats and vulnerabilities. While the survey didn't specifically address training or awareness programs, only 19% of the respondents said they ran social engineering tests, while Internet and infrastructure testing is also common practice at 85% and 73% respectively.

While E&Y says regulatory compliance has been the leading driver for information security since 2005, it reports that protecting reputation and brand has become a significant driver as well. However, the question asked was not what drives information security initiatives and spending, but rather, what are the perceived consequences of security incidents? What is the "level of significance if information is lost, compromised or unavailable" Eighty-five percent of respondents said damage to reputation and brand was "significant" or "very significant," followed closely by loss of stakeholder confidence, loss of revenue, regulatory action and legal action.

Though the report cites compliance as a driver for raising security awareness and improvements, there's room for healthy skepticism about how much companies would do if they weren't compelled. Every car should have seatbelts, but how many had them before they were mandated?

Other key findings:

  • Business continuity is an IT responsibility in 41% of the organizations, compared to 20% in risk management and 11% in information security. It would be interesting to see if this is trending toward or away from IT.
  • Most organizations are unwilling to outsource key information security activities. This is somewhat interpretive. While two-thirds to three-quarters of the respondents are keeping things like vulnerability and patch management, incident response, DR/BC, security awareness training and e-discovery and forensics in-house, the majority are either outsourcing or planning to outsource security assessments, audits and pen testing.
  • Few companies hedge information security risks with cyber insurance. Generally, around 10% of the organizations have some sort of insurance in one or more of eight information security-related areas, such as the cost of incident response or litigation, and few of the others have plans in the next 12 months. About one-third said they don't know, which leaves some potential for growth in the future.

    Tags: Security Industry Market Trends, Predictions and ForecastsISO 17799COBITVendor Management: Negotiations, Budgeting, Mergers and AcquisitionsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Security Industry Market Trends, Predictions and Forecasts
    Hackers to sharpen malware, malicious software in 2010
    Part 1: Marcus Ranum on the state of information security
    Part 2: Marcus Ranum on the state of information security
    Part 4: Marcus Ranum on the state of information security
    Part 3: Marcus Ranum on the state of information security
    Part 5: Marcus Ranum on the state of information security
    Layoffs prompt insider threat fears, cybersecurity survey finds
    Healthcare security spending remains sluggish, report shows
    How to use Internet security threat reports
    M86 buys Web security gateway vendor Finjan
    Security Industry Market Trends, Predictions and Forecasts Research

    ISO 17799
    Tony Spinelli: Prioritize Information Security over Compliance
    How to write a risk methodology that blends business, security needs
    IT auditing applications and tools for ISO 27002 certification
    Mix of Frameworks and GRC Satisfy Compliance Overlaps
    GRC: Over-Hyped or Legit?
    Is the Orange Book still relevant for assessing security controls?
    How do ISO 17799 and SAS 70 differ?
    How to apply ISO 27002 to PCI DSS compliance
    How to migrate from SAS 70 to ISO 27001
    Should ISO 17799 play a role in risk assessment?

    COBIT
    Tony Spinelli: Prioritize Information Security over Compliance
    Mix of Frameworks and GRC Satisfy Compliance Overlaps
    GRC: Over-Hyped or Legit?
    Is the Orange Book still relevant for assessing security controls?
    Does SOX provision email archiving?
    COSO and COBIT: The value of compliance frameworks for SOX
    ISO 17799: A methodical approach to partner and service provider security management
    Mapping the path toward information security program maturity
    RSA Conference 2006
    Step 1: Understanding compliance -- Financial and technical standards
    COBIT Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    backscatter body scanning  (SearchSecurity.com)
    marketecture  (SearchSecurity.com)
    NCSA  (SearchSecurity.com)
    Palladium  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts