Author: Alan Calder and Steve Watkins
ISBN No:
Review date: 26/07/2026
No of pages: 0
Publisher:
Year of publication:
Brief:
What we read in the papers is only the tip of the data insecurity iceberg - and yet most organisations do not have information security systems.
‘Little tends to be heard about businesses that suffer profit fluctuations through computer failure, or businesses that fail to survive a major interruption to their data and operating systems. Even less is heard about organisations whose core operations are compromised by the theft or loss of key business data, but who somehow survive it.’ Most organisations are structurally weak when it comes to info-security, the authors argue: the corporate lawyers do not co-ordinate with the physical security managers and IT.
Useful websites
While the book covers the British Standard 7799 for information security management, the authors are not parroting the standard. Dotted through the 28 chapters (featuring everything from equipment security to access control) are useful websites. No company is immune, because so many people have enough computing know-how to pose a threat, were they to apply themselves. Information security breaches can lead to financial (loss of credit card details) and reputational (your expensively developed brands defaced or counterfeited) loss. Several recent laws mean that you cannot ignore the issue, either: not only the Data Protection Act 1998, but the Computer Misuse Act 1990, and to do with human rights and copyright (not forgetting the Turnbull Report, that lays out that companies should have an ‘internal control system’ that ‘encompasses the policies, processes, tasks, behaviours and other aspects of a company’ to aid compliance, and safeguarding of assets from fraud amongst other things). BS 7799, the authors say, provides the framework, a system, for identifying threats and dealing with them. The authors say, helpfully: ‘Initial training of the key people, particularly the specialist information security adviser, is important and worth investing the time and money in before starting the process of implementation. Once the groundwork is laid, progress can be quick. The authors quote the Communications and Information Industries Directorate at the DTI (www.dti.gov.uk/cii) where you can download free guides – to risk, protecting information, and the Data Protection Act. They suggest classifying your information into three: routine info that you wish to keep private; marketing, customer and personnel info whose unauthorised disclosure would do you significant harm; and info such as patents, high-level strategies and sensitive assessments whose loss would inflict serious damage. As with the BS 7799, the authors’ concept of information security is all-embracing. If you check references, the chances are that you will find staff have incorrect CVs. How do you the manager act on that? The authors do not lay down the law, but stress the need for procedures so that you can work according to your organisation’s culture. New threats are emerging daily, the authors warn. ‘Every employee or contractor should be trained to be on the look out for suspicious incidents that, in their opinion, might affect information security, and to report them as soon as possible.’ Your reporting procedure should take in security breaches, threats, weaknesses, and malfunctions; and you should allow for emergencies to get more immediate attention.
<br><br><strong>
Thorough treatment
</strong><br><br>
While the book does not offer real-world examples, it is painstakingly thorough as you would expect from men in the thick of info-security. Alan Calder is director of DNV Certification, a company carrying out BS 7799 certifications; Stephen Watkins is Corporate Service Manager at the Crown Prosecution Service, where he is in charge of information security. ‘There are particular problems where two or more organisations share physical premises. In these circumstances, more than one secure perimeter may be necessary. For instance, there may be a manned reception desk that lets employees of both organisations onto the property according to jointly agreed procedures. Each organisation might then restrict access to its own floors, either through key cards or through its own reception desk. Where this type of additional perimeter is not possible, there may need to be individual security perimeters around individual information assets or information processing facilities.’ As a sign of the times, the useful website list runs to seven pages, the book list two. <br><br>
<strong>IT Governance:</strong> Data Security and BS 7799/ISO 11790, by Alan Calder and Steve Watkins (2002), published by Kogan Page. ISBN: 0 7494 3845 2.
<strong>Information Warfare:</strong> Corporate attack and defence in a digital world (2002), by Bill Hutchinson and Matthew Warren. These two Australians look at i-war from the non-military, business side. They consider i-war as an intelligence weapon; how political activists and others might wage i-awr; and how to defend against it. 224 pages, published by Butterworth Heinemann, ISBN: 0750649445.




