[ISN] IT directors call for mandatory data breach disclosure

From: InfoSec News (alerts@private)
Date: Mon Jun 02 2008 - 00:09:03 PDT


http://www.vnunet.com/vnunet/news/2217814/disclosure-uk-breaches-should

By Ian Williams
vnunet.com
29 May 2008

Nearly seven out 10 IT managers believe that data breach disclosure 
should be compulsory in the UK, according to a survey by Secure 
Computing.

The security firm polled 103 directors at this year's InfoSec security 
show in London in April.

Over 80 per cent of respondents said that data leaks by insiders, 
whether deliberate or accidental, is at the top of their list of 
security woes.

Only 17 per cent cited external threats posed by cyber-criminals, such 
as spammers and hackers, as more dangerous.

A third of respondents said that they had allocated budget to 
strengthening internal security and auditing.

The issue of legally enforcing data disclosures is contentious in 
Europe, as many believe that self-regulation is sufficient.

It has been suggested that the damage to an organisation's reputation if 
it suffered a data breach and did not inform customers would far 
outweigh the consequences of revealing the loss upfront.


_______________________________________________      
Attend Black Hat USA, August 2-7 in Las Vegas, 
the world's premier technical event for ICT security experts.
Featuring 40 hands-on training courses and 80 Briefings 
presentations with lots of new content and new tools.
Network with 4,000 delegates from 50 nations.  
Visit product displays by 30 top sponsors in 
a relaxed setting. http://www.blackhat.com



This archive was generated by hypermail 2.1.3 : Mon Jun 02 2008 - 00:16:15 PDT