DTI hardens line on security

UK firms may be compelled to take data protection more seriously

Written by Gareth Morgan, IT Week

The government may force companies to conform to security policy standard BS7799 to improve data protection, as worries over IT security failures grow in the wake of the SQL Slammer worm and other attacks.

David Hendon, director of communication and information industries at the Department of Trade and Industry (DTI), warned last week that unless business leaders made IT security a high priority, security standards BS7799 or ISO 17799 might become mandatory.

"There comes a point at which society cannot allow the corporate equivalent of train crashes to keep happening. Corporate responsibility will have to be considered," said Hendon, speaking at the Protecting Critical Information Infrastructures conference in London.

So far, only 80 UK companies have achieved certification for the BS7799 standard. Hendon said this low figure was "appalling", but admitted his own department was unlikely to devote money to seek accreditation until it was forced to do so.

Lawyers said the government may try to push firms to seek accreditation by using existing data protection laws, which require organisations to take measures to secure data. The Information Commission recently included a question on BS7799 certification in its annual data protection forms.

Jonathan Armstrong, technology lawyer at law firm Eversheds, said the commission could presume that if a firm has not signed up to BS7799, it is not taking effective measures to secure its data.

But businesses are likely to oppose the mandatory imposition of standards, especially since BS7799 compliance is a costly process that can take several years to achieve.

Jeremy Beale, head of e-business at the CBI, said security should be "achieved through encouragement" rather than legislation, by measures such as favouring accredited firms in government tenders.

Evershed's Armstrong said it was possible the government would favour suppliers that are BS7799 certified. "But that would leave room for allegations of restraint of trade." Armstrong added that it was legitimate for the government to ask for improved security. "[However] some firms may consider that they have introduced adequate protections without seeking accreditation."

Firms had been put off because of the perceived costs, said David Lacey, head of information security and governance at the Royal Mail Group. But after going through the accreditation process twice, he said this was a misconception: "It is a very efficient way of improving security procedures."

Have your say: reply to IT Week

Tags:

reader comments

related articles

Data Protection Act

Data Protection Act

How the Data Protection Act affects the way firms can process information and monitor their staff 25 Aug 2003

 

Commons rejects security standard

DTI support not enough to convince MPs to get BS7799 accreditation 23 Jul 2003

Comment: IT takes governing role

Moves to toughen up UK corporate governance rules will increase the pressure on IT directors to put in place systems that minimise business risks, says Mark Street 24 Mar 2003

Review 2007: IT security and e-crime

Computing's review of the year looks back at the top IT security and cybercrime stories 20 Dec 2007

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation