Radical new IT security guidelines announced for businesses
Stephen Timms, the Minister for e-commerce and Competitiveness, has launched new guidelines to ensure information systems are more secure against viruses and computer hackers.
The Minister introduced the updated guidelines, which he said were a 'radical overhaul' of the previous 1992 guidelines, at a recent Organisation for Economic Cooperation and Development (OECD) forum for global security issues.
The need to overhaul the existing e-guidelines for UK businesses was highlighted by the DTI's April 'Information Security Breaches' survey.
The survey results showed less than a third of businesses encrypted files containing confidential customer details and over a third of websites had no firewall in place, offering easy access to intruders.
The survey also showed viruses were the major cause of the most serious security breaches, with four in ten companies admitting they had been infected.
Seventeen per cent of businesses admitted they did not use anti-virus software.
Mr Timms said: "We are faced with a major challenge of making the information age a safe place to do business. Today's launch marks a turning point in how we rise to that challenge.
"Security systems play an integral part in the development of information systems, giving us a strong and healthy information technology environment.
"The UK has very actively supported and contributed to the revision of the original guidelines laid out by the OECD in 1992. The new guidelines provide a set of principles that will help us create a culture of security."
Jeremy Ward, a spokesman for the Confederation of British Industry, which acts as UK representative to the Business and Industry Advisory Committee, added: "Far too many businesses today are crossing the information highway without knowing anything about the risk. As a result, too many of them are becoming involved in nasty accidents involving information security.
An increased awareness of the need for security and what can be done to enhance it on a basic level;
Responsibility being taken by every individual on a network for the security of information systems and networks;
Co-operation and swift action placed as vital to the prevention and detection of security breaches;
Security of information systems made to be compatible with the essential values of a democratic society;
Risk assessments being used as an essential tool;
Security incorporated as an essential element of information systems;
Adoption of a comprehensive approach to security management needs; and
Reviewing, reassessing and modifying of security policies and practices.
Inclusions in the new guidelines
" The key issue is not so much what individual businesses must do to protect themselves, though this is still very important, it is creation of an environment of trust and security. Development of such an environment will require close and co-ordinated co-operation between industry and Government.
"The guidelines contain principles that businesses need to understand and on which they must act, in order to fulfil their side of the responsibilities involved in such a partnership. They are, if you like, the 'green cross code' of the information superhighway."
Mike Blackburn, Director of Secure IT Systems Ltd, welcomed the guidelines for UK businesses.
He said: "For its part, the security industry has to take more responsibility. Crying 'wolf' a little too often has led to widespread apathy on the part of businessmen and IT professionals alike. The threats to business are real both from the Internet and more importantly, from within!
"Many see security as a job for firewalls and anti-virus software, but the fact is, security is not just a technology problem, it is a business problem.
"For security to be effective it must become a state of mind on the part of the individual and dovetail into the corporate culture through the use of security policies and working practices that are aligned with business goals.
"Anything the Government does to promote this will only help raise the overall level of awareness and hopefully raise the subject up boardrooms' agendas where it belongs."