You are here: silicon.com > Management > Law & Policy

Law & Policy

By Nick Heath

Published: Monday 28 April 2008


Name

Haydn Rees


Location

London


Occupation

Technical Analyst


Comment

So long as, in the event of things going wrong the appropriate people go to prison, its fine.

The poor geek who tries to make an organisation take information security seriously should not be the one to stir the porridge.

It must be someone on the board (if they don't nominate a data security director/advocate, it must be all of them).

Make "Data Security Director" a position with statutory authority, responsibility, and power - requiring a little book learning and certification - to take executive action to make the organisation take security seriously, namely;

1. The use to which data is put in an organisation.

2. The downstream use (in other organisations) to which any data is put.

Audit trails. A named answerable published person who will twist in the wind if things go wrong.

Power to balance the authority and responsibility.

An assumption of culpability, which can only be mitigated by a log of the auditable measures taken to QA security risk, e.g. external Audit, and external Penetration Testing consultancy with a watching brief.



  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

The Round-Up The Weekly Round-Up: 03.12.09 'Ere guv, you'll never guess who I had in the back of my cab the other day…'

Stuart Roberts Shared services - how to get it right in your business Recession boosts uptake


Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.



Quick Sitemap Links: