Risk
7/11/2007
04:30 PM
50%
50%

Are You Spending Your IT Security Dollars Wisely? If You Don't Know, You're Not Alone

How do companies know they're getting their money's worth when they invest in IT security products and services? InformationWeek's upcoming 10th Annual Global Security Survey indicates that a surprising number of companies don't measure the value of their security investments at all. (Hint: it's up from last year).

How do companies know they're getting their money's worth when they invest in IT security products and services? InformationWeek's upcoming 10th Annual Global Security Survey indicates that a surprising number of companies don't measure the value of their security investments at all. (Hint: it's up from last year).It was one of the most surprising results I came across as I studied the data in preparation to write this year's security survey story, which will debut on InformationWeek.com July 14. IT budgets have always been tightly controlled; some companies won't even talk about how much they spend. But security is different. Companies have a longer leash when it comes to spending on security because no one wants to be the next company to make headlines because of a major data breach, either through lost or stolen information.

That's why the Veterans Affairs Department last year signed up SMS Inc. to a $3.7 million contract to install GuardianEdge Technologies and Trust Digital mobile encryption software on all laptops. Is that investment paying off? Hard to say because the VA has since found new ways of losing information about the men and women who've served this country. In January, an IT specialist with the VA lost an external hard drive that may have contained information on more than 1 million vets as well as non-VA physicians, and it's unclear how much of that information was encrypted. What is clear is that not all of that information was encrypted, a condition that pokes holes in the VA's efforts following the landmark theft of a VA laptop in May 2006 containing about 27 million records.

Maybe this is why not every organization measures the value of its security investments. In the 2006 Annual Global Security Survey, about half of the U.S. respondents measured value based on workers spending less time on security-related issues, while 41% used any decline in the amount of network downtime to justify security spending. Forty-percent cited better protection of customer records as an important factor in determining whether their security investments cut the muster. Yet 22% of U.S. survey respondents said they didn't measure the value at all.

Are IT security dollars that easy to come by, or have companies simply written IT security off as an exercise in futility? Be sure to check out the 10th Annual Global Security Survey next week to see how you compare with your peers.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3586
Published: 2015-04-21
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.

CVE-2014-5361
Published: 2015-04-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) start, (2) stop, or (3) restart services via a request to remote/serverServices.aspx.

CVE-2014-5370
Published: 2015-04-21
Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. (dot dot) in the QUERY_STRING to cfchart.cfchart.

CVE-2014-8111
Published: 2015-04-21
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.

CVE-2014-8125
Published: 2015-04-21
XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted BPMN2 file.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.