All the latest UK technology news, reviews and analysis

Regulation harming computer security, say experts

by Iain Thomson

More from this author

29 Jul 2009

Comment: 1

  • Tweet this
Black Hat USA 2009
CSOs need to get on with the job of protecting the company

Increasing levels of regulation from governments and within companies is harming computer security, according to experts.

Chief security officers (CSOs) complained at the Black Hat USA 2009 conference that they spend too much time doing jobs relating to regulation, and that doing so is detrimental to security.

"The security industry is beholden to do things that are not effective due to audits and regulation," said John Stuart, CSO at Cisco.

"I stopped paying attention to intrusion detection system logs. I don't care how many times we get attacked. Now I spend time looking at traffic leaving the company to find what's infected. It took nine months to convince the auditors about this."

Stuart added that each task had to be measured on efficacy. If he is asked to do something that reduces his efficiency he finds another "sucker group" within the company to do the job.

Bob West, founder of security intelligence firm Echelon One, agreed with Stuart. "I could spend a whole lot of time on compliance, but I wouldn't be spending it doing my security job," he said.

Companies need to analyse the compliance issues that need to be addressed and remove them from the CSO's job where possible. This frees up the CSO to get on with the job of protecting the company.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Systems Analyst - Project Lead - Chelmsford - £50k-55K+Bens

Systems Analyst - Project Lead - Chelmsford, Essex...

Windows Systems Engineer (Windows Log File, Syslog) learn SIEM

Windows Systems Engineer (Windows Log File, Syslog) learn...

PHP Developer - Zend, MVC

Role: MVC PHP Developer Location: London, Central...

Senior Web Developer / Engineer (HTML, JavaScript, CSS)

Title: Senior Web Developer / Engineer (HTML, JavaScript...

To send to more than one email address, simply separate each address with a comma.