- 595 immigrants arrested at electronics plant
- Techiest celebrity endorsements
- Network failure delays flights across U.S.
- Alcatel-Lucent intros Gigabit Ethernet switches
- Firefox browser gets security boost
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
A new study shows that most large companies don't spend enough of their IT budgets on upgrading their security infrastructures - a situation that could lead to bigger problems in the face of government legislation and corporate mergers and acquisitions.
Nemertes Research last week released its "Effective Security Solutions" report, which says the average 2% to 3% of the overall IT budget that companies allocate for security will not adequately prepare most of them for government regulations, new applications and/or Web services architectures.
Johna Till Johnson, Nemertes Research president and chief research officer, and a Network World columnist, says spending 3% on security will allow for only the security basics at most large organizations. Nemertes' definition of security basics includes deploying firewalls and VPNs, and controlling the security perimeter.
"Everyone will say that security is essential, and no one will dare say it's not important, but they are still underspending on security," Johnson says.
Nemertes found that many companies in the past five years have made strides in designating security officers, staff and budget, but still fall short when it comes to funding new and necessary projects. She says companies must spend at least 5% of their overall IT budgets on security to incorporate the infrastructure upgrades and policy-based processes necessary to comply with government regulations passed in the past eight years or so.
The security requirements in legislation, such as the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Gramm-Leach-Bliley Financial Modernization Act of 1999, the Sarbanes-Oxley Act of 2002 and ongoing Department of Homeland Security initiatives, represent a significant concern for companies currently underspending, Johnson says.
HIPAA establishes national standards to ensure privacy in electronic healthcare transactions, and in light of all the accounting discrepancies in recent years, Sarbanes-Oxley requires that managers vouch for the internal controls their companies place over areas that include transactions, electronic information and communications. Sarbanes-Oxley will become a Securities and Exchange Commission rule. The Gramm-Leach-Bliley act broke down information-sharing barriers among U.S. banking, securities and insurance industries so as to provide various financial services to customers, but also requires many electronic financial privacy regulations be put in place.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment