Article Written By: eccuni
Employee training is crucial to ensure data protection and privacy. Increased use of social networking sites for business promotion activities means increased interaction with various stake holders. Online degree programs may help employees in understanding and implement information security practices. Organizations must guide employees on social engineering threats, which pose risk to data security and privacy through e-learning programs. Professionals qualified in computer science degree and IT security certifications may help organizations in removing hurdles in implementation of information security policies, identifying threat vectors and initiating remediating measures. Organizations may collaborate with educational institutions in devising new online university degree courses offering specialization in privacy certifications and data security in order to avoid security issues such as information security professionals at Sony have discovered unauthorized access to customer databases of Sony Online Entertainment (SOE). Preliminary investigations have revealed that attackers were successful in extracting around 12,700 records of non-U.S customers, which include credit or debit card numbers and card expiry dates. Attackers reportedly also extracted 10,700 records, which include bank account numbers of customers in Germany, Austria, Spain and Netherlands. Sony had recently reported unauthorized access to 77 million customer accounts caused by the breach of PlayStation network. The company has temporarily closed SOE game services and has hired an external security firm to conduct thorough investigation of the security breach.The latest revelation has taken the tally of number of company's customers exposed to identity theft, fraud and other crimes to over 100 million. The recent spate of data breach incidents has raised alarm bells across the world. Information security is crucial to retain customer trust and ensure business continuity. However, businesses face challenges in improving information security infrastructure. A PricewaterhouseCoopers (PwC) survey on global information security indicates that while business executives appreciate the significance of information security, they are cautious in increasing funding. Cost reduction efforts, distressed suppliers and business partners act as constraints in increasing funding for information security. Economic constraints force businesses to either reduce or defer security initiatives. Data breach incidents not only put personal information of customer's at risk, but also raises privacy concerns. A report on Data privacy Trends for 2011 by Ernst and Young (EandY) emphasizes on data protection. The report says, failure to give adequate emphasis to data protection may not only cause financial damages, but also have adverse impact on brand image. The report foresees improved enforcement of data protection laws, imposition of financial penalties, additional breach notification requirements by governments and increased privacy assessments by internal audit departments. Increased adoption of cloud computing requires organizations to have strong vendor risk management mechanisms. Organizations need to understand the limitations of mobile devices in protecting privacy.
This Article Has Been Published on Tue, 3 May 2011 and Read 247 Times