* Survey sponsored by PortAuthority Technologies
endif; ?>One of the constant problems we face in our field of security management is that we lack reliable data about what we’re doing.
I’ve written at length about this issue of data collection and reporting and invite readers to see my summary of the problems here or in PDF. As one who has long taught applied statistics, including survey design, I am particularly pleased to find a well-constructed and properly reported study of security issues.
PortAuthority Technologies recently sponsored a study by Larry Ponemon of the Ponemon Institute to examine the state of information security management in the U.S. today. The four key issues were (quoting page 2):
1. How do information security practitioners respond to data breaches?
2. What technologies, practices and procedures are employed by organizations to detect and prevent data breaches?
3. What are the issues, challenges and possible impediments to effectively detecting and preventing data breaches?
4. How do organizations attempt to enforce compliance with its data protection policies?
This Web-based survey resulted in 749 qualified respondents who said that they were “involved in [their] organization’s data protection activities, programs or initiatives.” Half of the respondents’ job titles were security- or IT-related; 77% were supervisors, managers, directors, vice presidents or senior executives. Industry sectors included financial services, government, manufacturing, technology, healthcare, education and many others. Over 95% of the respondents worked in organizations with more than 1,000 employees; 60% were employed in organizations of more than 25,000 employees.
One of the more startling findings is that 34% of the respondents said that their organizations do not use any technological means of preventing and detecting data breaches. Of these respondents, 35% said that the technology was too expensive; 16% claimed that manual procedures were “more than adequate for our company’s data breach detection and prevention”; and 16% asserted that “Our company is not vulnerable to data breaches.” That last assertion is breathtaking in its hubris, don’t you think?
Of the respondents, 76% claimed that they could detect a large data breach (more than 10,000 customer records) with a probability of 60% or more; however, only 36% of the same sample thought that small data breaches (fewer than 100 customer records) would be detected 60% of the time or more.
The report shows graphs comparing “how respondents view the effectiveness of their organization’s enforcement practices. While over 59% of respondents believe their company is effective at detecting breaches, only 37% believe the company is effective at preventing breaches.”
Of those who did use technology to detect data breaches, 39% used content filtering technologies; 28% used keyword monitors; 25% used “data leak detection and prevention” and 23% used intrusion detection systems. Other tools mentioned included packet sniffers and digital-rights management products.
The most common methods mentioned for preventing data breaches were access controls (41%), virtual private networks “or other secure token-based networks” (27%) and encryption (22%).
Thankfully, 81% of the respondents named policies and standard operating procedures as a method for preventing data leaks; 71% mentioned “close supervision and management of all data handling functions.” In addition, 65% provided “training and communication programs” and 40% insisted on “rigorous background checks for all employees who handle sensitive or confidential information.” However, only 33% of the respondents thought that their organization was “effective” at enforcement of security policies.
Another interesting question concerned why enforcement of security policies may not be effective. Some 29% of the respondents said that the primary reason was that there are many methods for bypassing security; 28% mentioned the false-positive problem. Another 16% named cost as a key issue and 14% complained that upper management did not seem to support the policies.
There are many other interesting findings in the study. Go here to register for and download the PDF version of the report. This report will make excellent material for brown-bag lunchtime discussions among the security team members in any organization and can be useful for teachers and students in security-management courses. Practitioners and students will do well to apply all the study questions to themselves and to examine their own responses carefully.
Congratulations to Ponemon and thanks to PortAuthority Technologies for sponsoring the study.




