TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Integrated Systems

ICO letters

by Msecadm4921

Christopher Graham, the information commissioner, announced plans to issue a letter to local government chiefs warning them to get the poor data handling within councils under control. The letter follows similar action taken by the Information Commissionerโ€™s Office (ICO) last year when it sent a letter to Data Protection Officers (DPOs) in the health sector.
ย 

Ross Brewer, vice president and managing director for international markets, LogRhythm, has made the following comments:
ย 
โ€œCompared with the positive steps the EC is taking with the new Data Protection Directive, this announcement from the ICO feels pretty limp. Healthcare based data leaks have continued to make the news since the letter to DPOs in September so it canโ€™t be claimed that this approach has had success in the past.
ย 
โ€œRecent research from OnePoll [OnePoll, October 2011, survey of 2000 UK consumers] found that the public is hungry for real action in this area. When asked if organisations are doing enough to secure sensitive data 81 percent said they thought that they needed to try harder. When asked about specific sectors, only 25 percent of respondents stated that they thought public sector organisations could be trusted to keep data safe. The ICOโ€™s letter writing campaign is unlikely to placate a public that seems to have had its fill of irresponsible data protection.โ€
ย 
While Brewer is unimpressed with the ICOโ€™s decision to send letters to local government authorities, he did agree with Christopher Grahamโ€™s assertion that โ€œgood data practices have benefits beyond avoiding finesโ€.
ย 
โ€œMany organisations need to move away from compliance led IT to a best practice model. By embracing approaches like Protective Monitoring they will find they receive a host of benefits as well as enhanced data security. By continuously monitoring 100 percent of log data generated by systems it is possible to identify seemingly unconnected events that indicate anomalies and enable real-time remediation. However, this approach also helps organisations to spot operational inefficiencies that may be directly responsible for the loss of time and money,โ€ said Brewer.ย 

Related News