Information Security

After five years of conducting the "Global State of Information Security" survey, we have noted some critical trends in information security. We've also uncovered nontrends-numbers that remain so constant and predictable that we can now call them conventional wisdom. Here, then, are five pieces of wisdom based on numbers in the survey that never seem to change.

By Scott Berinato, CIO.com,

After five years of conducting the "Global State of Information Security" survey, we have noted some critical trends in information security. We've also uncovered nontrends-numbers that remain so constant and predictable that we can now call them conventional wisdom. Here, then, are five pieces of wisdom based on numbers in the survey that never seem to change.

Spending lags. You're always about 10 percent happier with security policy's alignment with the business than you are with security spending's alignment. Over the years, roughly 85 percent of you have said that your security policies are completely or somewhat aligned with the business, while just 75 percent said that about spending. After all, who doesn't want more money?

Partners too. You're more confident in your own security than that of your partners, suppliers and vendors. Once again, around 80 percent to 85 percent of you were either very or somewhat confident in your security, but when you were asked about partners and vendors, the number dropped to between 70 percent and 75 percent. Remember, you're someone's partner and he's not too thrilled about you either.

Few are cocky. About one in 12 of you think very highly of yourselves. Since 2003, the number of respondents who claimed 100 percent of their users were in compliance with their security policies hovers around 8 percent.

Size doesn't matter. Company size does not affect spending. When the information security budget is measured as a percentage of the IT budget, it remains constant no matter how many employees a company has or what its revenues are. Size of company matters less in security spending than in industry. Technology companies spend the most; nonprofits and educational enterprises spend the least.

Banks lead. Financial services companies are attacked more but suffer less. Over the years, respondents in the money business have reported more security incidents without an appreciable increase in losses or downtime as a result. They do this despite not having significantly larger security budgets than others. The financial sector models best practices.

Copyright © 2007 IDG. All rights reserved.

Related Articles
- Identity Theft
There are several kinds of identity theft even more severe then credit card theft. Educate yourself and use the appropriate identity protection services that can actually restore your identity if anything were to happen. Read this article to learn more about this topic.
- Business Security Services
- Information Security Best Practices
- Provision Security Solutions
- Private Security Officer
- How To Buy Security Barricades
- Smart Outbound Content Management
- Employee Verification for SMBs
- Ways To Protect Computer
- Training For Security In Computer World
Regional Articles
- Information Security Alabama
- Information Security Alaska
- Information Security Arizona
- Information Security Arkansas
- Information Security California
- Information Security Colorado
- Information Security Connecticut
- Information Security DC
- Information Security Delaware
- Information Security Florida
- Information Security Georgia
- Information Security Hawaii
- Information Security Idaho
- Information Security Illinois
- Information Security Indiana
- Information Security Iowa
- Information Security Kansas
- Information Security Kentucky
- Information Security Louisiana
- Information Security Maine
- Information Security Maryland
- Information Security Massachusetts
- Information Security Michigan
- Information Security Minnesota
- Information Security Mississippi
- Information Security Missouri
- Information Security Montana
- Information Security Nebraska
- Information Security Nevada
- Information Security New Hampshire
- Information Security New Jersey
- Information Security New Mexico
- Information Security New York
- Information Security North Carolina
- Information Security North Dakota
- Information Security Ohio
- Information Security Oklahoma
- Information Security Oregon
- Information Security Pennsylvania
- Information Security Rhode Island
- Information Security South Carolina
- Information Security South Dakota
- Information Security Tennessee
- Information Security Texas
- Information Security Utah
- Information Security Vermont
- Information Security Virginia
- Information Security Washington
- Information Security West Virginia
- Information Security Wisconsin
- Information Security Wyoming
Related Articles
- Employee Verification for SMBs
The IRS suggests that small-business owners verify employee names and Social Security numbers. Using the institution's online verification is beneficial for several reasons.
- Ways To Protect Computer
- How To Buy Security Barricades
- Smart Outbound Content Management
- Private Security Officer
- Provision Security Solutions
- Identity Theft
- Business Security Services
- Training For Security In Computer World
- Information Security Best Practices

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History