Monday November 24, 2008 3:40 AM AEST
Latest Comments
"it's good one "
by khanbhai | Nov 22, 2008 9:00 PM
 
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM

Retailers lagging behind in security

  • Email a Friend
  • Print Page
By Phil Muncaster
Feb 4, 2008 10:07 AM
Tags: Retailers | lagging | behind | in | security
Retail is lagging behind other sectors in the maturity of its information security function, despite high awareness about data protection issues among IT leaders, according to the latest report from consultancy firm Deloitte.

The Taking Stock: Consumer Business Security Survey surveyed IT leaders and chief security officers from consumer goods and retail firms and found 73 per cent rated "unauthorised access to personal information" as the top privacy and reputational concern.

But despite this, only 20 percent of respondents said they have a formally defined information security strategy, compared to the 54 per cent reported in Deloitte's 2007 Technology Media & Telecommunications Security Survey and 63 per cent reported in Deloitte's 2007 Global Financial Services Security Survey.

Only 13 per cent of consumer businesses said they had performed an inventory of personal and cardholder data. In addition, 40 per cent of respondents said they had had written privacy, fair information practices or data collection policies in place and only 13 per cent have a programme for managing privacy compliance.

However, many firms are still in the delivery phase of their Payment Card Industry (PCI) standard implementations, which might account for the lack of formal security policies to protect data, according to Deloitte's consumer business partner, Andy Morris.

"Overall I think it's fair to say there's a long way to go in terms of the maturity of security in the industry," he added. "But some drivers like PCI are encouraging organisations to change and improve and in 12 months things will look a lot more positive."

However, Morris expressed surprise over the lack of security due diligence consumer businesses seem to show before taking on an outsourcing contract. Only 36 per cent said they conduct an independent review of vendors before engaging them, according to the research.

itweek.co.uk @ 2008 Incisive Media

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Patch Management Whitepapers