The InformationWeek -- Blogs
CIOs Uncensored

Topics:   CIOs Uncensored

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Security Training: Whose Responsibility Is It?


Posted by John Soat, Nov 5, 2007 07:56 PM

Who else other than the CIO? So why aren't CIOs doing more about it?

Mark Twain is reported to have famously remarked: "Everybody talks about the weather. But nobody does anything about it."

I was reminded of that quip when I read a news story posted by my colleague K.C. Jones about the increased awareness of security problems related to mobile computing devices and wireless networks, and the lack of effort to do anything about it. The story was related to the release of a survey sponsored by an industry organization called the Computer Technology Industry Association (CompTIA). The organization claimed to have interviewed 1,070 organizations about their security concerns.

Sixty percent of organizations surveyed recently said that security issues related to handheld devices have increased over the last 12 months... Still, only 32% of organizations have implemented any security awareness training for mobile and remote workers, according to CompTIA. Only 10% plan to implement security training in the next 12 months...

How could this be? Is it a question of resources, funding, executive support? Or is it a game of pass the buck? "That's an HR issue, not mine," huffs the hand-wringing, head-in-sand CIO.

Yet, the proof is there that security training can be effective, according to CompTIA. “Nearly 90 percent of organizations that have implemented awareness training for remote and mobile workers believe that the number of security breaches they’ve encountered has been reduced.” said John Venator, president and CEO of CompTIA, in a statement. “Organizations that do not train their mobile workers in security fundamentals are doing themselves a great disservice,” he said.

Security training in general doesn't seem to be a particular priority among CIOs. In the most recent InformationWeek Information Security Survey 2007, only 19% of the 1,101 business technology executives contacted in U.S. cite "Educate business groups" as a key tactical security priority in the next 12 months. In answer to the question, "How often does your organization train employees on information security policies/procedures?" 47% of U.S. respondents answered "Ad hoc," and 5% said "Never." If my math is correct, that adds up to more than half of the U.S. survey respondents training their employees on computer security policies and procedures, uh, mostly when they feel like it.

What will it take to make computer security -- in particular, security related to mobile computing and wireless networks-- a priority? And for CIOs to take responsibility for it -- and do something about it?

« Five Reasons Palm Should Drop Its OS And Use Google Android | Main | What Does Google's Android Mean For The Open Source Community? »



Sign up now for the weekly InformationWeek Blog Newsletter.


This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




InformationWeek Chief Of The Year:
Call For Nominations
Know a dynamic, future-oriented tech chief? We're looking for the most insightful, innovative, forward-thinking business technology leader to honor as our 2008 Chief Of The Year. "Tomorrow's CIO" is the theme of our InformationWeek 500 Conference, and of a recent in-depth InformationWeek Analytics Report based on our extensive survey. The qualities identified with Tomorrow's CIO—equal parts leadership, vision, business savvy, technology expertise--are what we're looking for in our Chief Of The Year.

Candidates must be CIOs, CTOs, or VP-of-IT level executives. Nominations will be accepted now through Oct. 31, 2008.

Please send your nominations to: cjmurphy@techweb.com.



Sign Up For The CIOs Uncensored Newsletter
Every Thursday, Chris Murphy and his fellow analysts explore the business, strategy, and management issues most important to IT leaders.

Sign up for our free, weekly newsletter today!

Newsletter Archives


Global CIO Video



  1. First Firmware Update For The BlackBerry Storm Blows Into Town
  2. Alcatel-Lucent's Big Plans
  3. Google Gives Windows Users A Gmail Gadget For The Desktop
  4. Nokia Unveils The N97, Its Real iPhone Competitor


  1. Telstra Readies 21Mbps Wireless Network Down Under
  2. Apple Axes Antivirus Help Page
  3. Amazon Launches Experimental Mobile Shopping Feature
  4. BlackBerry Maker Offers $53 Million For Certicom
  5. Cyber Monday Web Traffic Reports Mixed
  6. Yahoo, CBS Radio Agree To Online Music Deal

 
 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
APRIL 2008
MARCH 2008
FEBRUARY 2008
  JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007
AUGUST 2007
JULY 2007
JUNE 2007