Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 04, 2008

How Effective Are Your Security Policies?

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

Cisco, a leading security provider, recently conducted a two-part research study that assessed the effectiveness of IT security policies. This study, which analyzed the behavior and perceptions of 2,000 employees and IT professionals in 10 countries, found that employees engage in numerous risky behaviors at work, including the following:

  • Altering security settings to bypass corporate security policies and access unauthorized sites
  • Accessing unauthorized areas of networks and facilities
  • Sharing sensitive corporate data with non-employees
  • Sharing corporate devices with non-employees
  • Losing portable storage devices
  • Allowing others to "tailgate" behind them into corporate facilities
  • Leaving devices with passwords to personal financial accounts and corporate systems unattended and unlocked

In addition, Cisco’s research revealed some surprising findings about the effectiveness of corporate security policies. For example:

  • One in four organizations don’t have any data protection or security policies in place.
  • A large gap exists between employees and IT personnel regarding security policy awareness: Between 20 percent and 30 percent more IT respondents than employees are aware of their company’s security policies.
  • A communication disconnect often exists because IT personnel tend to communicates policies in an indirect, non-verbal manner (e.g., email, voicemail, memo). This lack of direct, verbal engagement contributes to the gap in IT personnel/employee security policy awareness.
  • The main reason that employees don’t adhere to corporate security policies is a lack of alignment between those policies and the reality of doing their jobs.
  • One in five IT professionals has experienced a data leakage incident that involved the loss of customer data.

In the following video, Cisco CSO John Stewart explains why data leakage is such a serious issue and what companies can do about it.



 

 

 

For more information about Cisco’s study, go to Cisco's Data Loss Prevention website, where you can review all the study findings. To view Cisco’s entire video series about the study, see Part 1: “Data Leakage Mistakes Employees Make Globallyand Part 2: “Data Leakage and Corporate Policies: Are they Aligned?

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.





Search Industry Bytes
 
Industry Bytes
JANUARY 2009
     1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
       
or

 Recently in Industry Bytes
A 5-Step Security Plan
Make a Comment
Great IT Words: #158 from Jeff the Security Expert: Munge
Make a Comment
Hosted and Bundled: A Complete Messaging and Collaboration Solution

Last Comment
nSynergy SharePoint Document management and collaboration software architectures allow organisations...
(2 Comments)
Internet Explorer Patch now Available
Make a Comment
Better Email Archiving Through Easier Content Tagging
Make a Comment

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing