Research
Human Firewall Council Sees Security Immaturity
A Human Firewall Council survey of the state of information security, as measured against ISO guidelines, shows plenty of room for improvement. Is the problem a lack of overarching vision, a dearth of adequate resources or a little of both?
By Derek Slater
As with many large companies, Northern Trust uses the ISO 17799 standard as a guideline for its information security efforts. Still, Locke notes that full compliance is not necessarily realistic for everyone. His own company earns a B-minus
Finally, there is one more significant caveat to bear in mind with the survey results: The assignment of letter grades is quite subjective. For example, a company that checks "partially implemented" for a particular set of ISO best practices automatically receives a score (5 out of 10) that maps to a failing grade for that category. "In my opinion, partial implementation might be more deserving of a C," admits Rasmussen.
Nevertheless, the index makes its point. "You can look at the methodology and say it's skewed one way or another," says Rasmussen, "but I would say the results are fairly accurate based on what I find in the field."
Other stories by Derek Slater
security maturity
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



