ISR News: 64% of Executives Ignore Security
Excerpts From SANS.org
According to Carnegie Mellon University’s CyLab Governance of Enterprise Security Survey, “boards (of directors) are taking risk management seriously, but there is still a gap in understanding the linkage between IT and enterprise risk management.”
Just 36 percent of respondents indicated that the board of directors at their company was directly involved in the management of the company’s information security. The statistics were gathered from a pool of 703 respondents who serve on boards of US-listed public companies.
Among the recommendations offered in the study are including IT risks in enterprise risk management planning and establishing a cross-organizational team that will coordinate and communicate about privacy and security.
Filed under: Breach, D&O Liability, Financial, ISR News, Insider Threat, Sarbanes-Oxley, Uncategorized, identity-theft, malware, national security, privacy
Comments
Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!













