22 October 2010

Enterprise Security Survey 2011

PricewaterhouseCoopers (PwC), in association with CIO Magazine and CSO Magazine, has released its 2011 Global State of Information Security Survey report.

The report is based on data collected in early Spring 2010 from almost 13,000 CEOs, CFOs, CIOs, CSOs, vice presidents and directors of IT and information security in 135 countries. It analyses trends and drivers in strategic security spending.

Partial view of a bar chart from the PwC 2011 Global State of Information Security Survey.

The data on adoption of certain security and privacy protection capabilities in place is interesting. The capabilities listed include some governance and human-related matters such as checks and training, but apart from "established security baselines for external partners, customers, suppliers and vendors", the remaining capabilities appear to be post-implementation activities such as monitoring, centralised information management and event correlation.

There is no mention of practices meant to build security in to business process development and acquisition (e.g. such as those described in the Software Assurance Maturity Model), or about maintaining and checking the accuracy of information. Perhaps there were not any questions in the survey about these aspects?

However, I am sure the high-level data will be useful for executives developing business cases for investment in security, especially helping judge what their colleagues' interests and concerns might be. The data is also broken down regionally.

Chris Potter, a PwC Partner, is speaking at ISACA London's chapter meeting next week on "Latest Trends in Security Breaches and the Implications for IT Governance and IT Assurance". I expect we will hear more information about this report and have the opportunity to ask further questions.

Posted on: 22 October 2010 at 07:47 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Enterprise Security Survey 2011
http://www.clerkendweller.com/2010/10/22/Enterprise-Security-Survey-2011
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2010/10/22/Enterprise-Security-Survey-2011
Requested by 38.107.179.223 on Thursday, 17 May 2012 at 22:00 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2010-2012 clerkendweller.com