Protecting enterprise data and systems while maintaining employee productivity is a delicate balance for CIOs, finds Robert Half survey.

Mathew J. Schwartz, Contributor

August 30, 2010

2 Min Read




Slideshows: 12 CIOs' 'Career Killer' Pet Peeves

For 12% of CIOs, hearing complaints from employees over IT security measures -- specifically, limits on their access to certain types of websites or networks while using the office network -- is a common occurrence. Meanwhile, 29% of CIOs say such gripes are at least "somewhat common."

The numbers come from a survey of more than CIOs, selected randomly from companies in the United States with 100 or more employees, conducted by staffing firm Robert Half Technology.

"There will always be employees who feel IT security policies are too restrictive," said John Reed, executive director of Robert Half Technology, in a statement. "But in most situations, robust information security measures are necessary to protect sensitive data and an organization's network integrity from increasingly sophisticated threats."

On the other hand, said Reed, if too many people are complaining, then maybe it's time to reevaluate whether an organization's security policies have come down on the wrong side of the security-versus-productivity equation.

Rather than worrying whether their security policies are too restrictive, however, many organizations have a more fundamental problem: they lack any security policies, or else mechanisms for automatically enforcing those policies.

The result in either case is the same: employees often take their chances, ignoring any rules that they think are slowing them down, such as social networking restrictions or file transfer rules. According to numerous studies, when it comes to flouting security policies, IT personnel can be amongst the worst offenders.

But if corporate security or web access rules are cramping your style and making it harder to do your job, Reed recommends speaking up. "Some policies may simply be outdated and no longer make sense," he said. "Asking someone in your organization's IT department why access is restricted is often one of the quickest ways to resolve an issue."

If policies aren't judged to be outdated, he suggests talking up the business reasons for why they should change. "If employees can't access a client's website or a professional networking site that can generate business, it will probably be an easy case to make," he said.

About the Author(s)

Mathew J. Schwartz

Contributor

Mathew Schwartz served as the InformationWeek information security reporter from 2010 until mid-2014.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights