All the latest UK technology news, reviews and analysis

Stiff fines await boards

by Chris Lee

22 Nov 2001

Be the first to comment

  • Tweet this

Company boards face a minefield of legal responsibility under the new data protection laws, especially when outsourcing security, a panel of industry experts warned.

Speaking at a debate on the future of internet security in London, security experts, lawyers and analysts said companies needed coherent and comprehensive security policies which were enforced, or face stiff fines.

"If a policy is going to mean anything at all, someone has to be accountable for it," said Mike Awford, UK channel operations manager for security specialist RSA. "At the end of the day, ownership belongs with the board."

James Davis, a director at analyst group Gartner, agreed. "The chief information security officer is a new role emerging in modern businesses, like that of a risk officer, answerable to the CEO," he said.

"Total security is impossible, but there must be a policy, someone responsible for it, and it must comply with industry standard BS 7799."

According to Mark Smith, a solicitor at law firm Morgan-Cole, the Data Protection Act is set to shape the security market in the coming months.

"IT managers will be required to show that they have taken adequate steps to protect their own and their customers' data," he said.

"Directors need a lot more diligence, particularly when outsourcing. Here they must be more creative over sharing risk with their hosts according to their service level agreement [SLA]. The contact will become more and more key."

Davis said that companies must remember that security is a process, not a product. "It's not about technology, it's about governance," he said.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

FX Technical Implementation Consultant FX FOREX Trading London

FX Technical Implementation Consultant (Business Analyst...

IT Support Analyst - Leyland, Lancashire

IT Support Analyst required by Leyland, Lancashire Software...

Web Developer ( PHP5, OO, MySQL ) - Shrewsbury

A talented PHP / Web Developer is required for a web...

Software Developer ( .NET, C#, VB6, SQL ) Cheshire

Software Developer ( .NET, C#, VB6, SQL) needed. This...

To send to more than one email address, simply separate each address with a comma.