Skip the navigation
Opinion

Wanted: Global rating system for security

By Jay Cline
August 5, 2002 12:00 PM ET

Computerworld - With corporate accounting practices under fire, are security practices next? The kindling may already be in the pit.


Data security remains largely undefined and unenforced across private industry. The result? Companies underinvest in security, and a steady stream of publicized security breaches keeps customers from trusting e-commerce.


What we need is an independent system that gives "triple-A" or "junk bond" ratings to companies' data security. The private sector needs a global rating system to let customers know whom to trust with their data.


We won't find this rating system in the world's privacy laws. Nearly every such law requires companies to impose their security standards on their suppliers -- but the laws don't detail what those standards should be. Europe, Canada and Australia require companies to deploy data security that is commensurate to the risk of data compromise, but they don't define what that means. Complying with these meaningless standards won't give companies what they need to win customer trust.


Likewise, the largest companies are doing a lousy job of conveying the value of data security. Only 29 of the Global 100 say anything in their online privacy statements about their data security. Just 13 claim to encrypt your data in transit, something you learn to do in Security 101. Most simply say they use "appropriate measures" to protect customer data, and there is even an emerging trend to add weasel words such as "but your data is never 100% safe." These tactics may be a good legal defense, but they won't build market confidence.


Governments and corporations struggle to talk about security because no one recognizes a common security language. The British Standards Institute's BS7799 code is so comprehensive a masterpiece that no one can afford to adopt it. The Visa Cardholder Information Security Program is more digestible, but it's not designed to communicate security value to the general public. Insurance companies, which have just started compiling risk tables for data security, are best positioned to fill this gap. What we need is a team from Visa, The St. Paul and Standard & Poor's to forge a security rating system that becomes as pervasive as the little padlocks on Web screens that indicate you're on an encrypted connection.


To become pervasive, we need these ratings built into the Platform for Privacy Preferences (P3P) now included in the latest version of Microsoft's Internet Explorer Web browser.


Why am I hung up on a rating system? Because it fixes a widespread market failure of imperfect information.


Boardrooms today have no way of knowing that a dollar invested in data security will generate even a dime of additional revenue. That's because there's no lingua franca for companies to tell customers they've done something extra to secure their data.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Privacy White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
All Privacy White Papers
Privacy Webcasts
A Road Map for Best Practice Social Media Acceptable Use Policy
Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
Data Protection and Disaster Recovery with iSCSI and VMware
Get this on demand webcast now
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
All Privacy Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs