ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

CIOs: Encryption only part of data-security solution

Andy McCue silicon.com

Published: 10 Dec 2007 08:49 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Policies, processes and a "corporate ethos" of care of data are more important in securing sensitive information than using encryption technology.

Encryption has been back in the spotlight following the data breach at HM Revenue & Customs that led to two CDs containing unencrypted records of 25 million people on the child-benefit database getting lost in the post.

But two-thirds of a 12-strong CIO Jury IT user panel, brought together by ZDNet.co.uk's sister site silicon.com, said technologies such as encryption need to be part of a more holistic approach to security, including training for staff and strict enforcement of policies.

Nic Evans, European IT director for Key Equipment Finance, said: "More important is a corporate ethos of care of such data."

Encryption on its own can give a false sense of security, according to Florentin Albu, ICT manager for the European Organisation for the Exploitation of Meteorological Satellites (EUMETSAT).

"However, when used in the context of an information-management [or] information-security framework, it can become an effective way to mitigate certain corporate-data risks. Even so, it would be just one piece of the jigsaw; you need to combine it with other technologies — authentication, authorisation, et cetera — and information-management practices — data classification, data handling, et cetera — in order to become effective," Albu said.

Even with encryption technology, there are weaknesses that could lead to data being compromised. Steve Clarke, director of systems and operations at AOL Broadband, said: "Encrypted data still needs to be viewed, which means it must be unencrypted — giving rise to opportunities to store the data without its encryption. By implementing policy, processes, appropriate training and rigorous enforcement, our data stands a chance of remaining secure, but encryption alone is not the panacea."

James Findlay, head of ICT for the Maritime & Coastguard Agency, said: "Encryption only forms part of the solution. Organisations must have robust policies and processes in place to ensure the integrity of both data and systems."

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Another survey by security company Check Point found that just under half of IT chiefs have deployed encryption within their organisations.

But those in favour of greater use of encryption to secure data included Graham Yellowley, director of technology services for investment bank Mitsubishi UFJ Securities International.

Yellowley said: "This is a minimum requirement for securing any data, whether this be for internal or external dissemination. Encryption strength needs to be considered, with at least 256-bit key encryption [needed] for real security."

Richard Steel, chief information officer for the London Borough of Newham, added that encryption should be used "where the data must be mobile, and [should be] combined with two-factor authenticated access".

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
2 out of 6 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Corporate Records Manager

Focused on our move towards the paperless office, you will ensure the Councils recording keeping processes are in order by conducting information ...

Service Desk Engineer / 1st Line Support - London

We have created a fun working environment, promoting good team working ethos and a flat company structure where everyone has a voice. Knowledge of ...

CRM Manager

We look forward to supporting employees transfer to our new headquarters and a relocation package will be provided in accordance with QCAs agreed ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec