
ISO 27001
Loss of sensitive information about customers, clients or employees of companies and institutions have regular news lately. These events are so common in that they are hardly newsworthy anymore, with the exception of the largest and very embarrassing. Many of these incidents appear to be the result of the large, even criminal negligence of those who lose data.
A majority of data loss incidents appears in the U.S. and Britain, are in hospitals, other institutions, the military and others. An international study showed that health professionals (Mobile Device Usage in the Healthcare sector), which was terrible improved security in general in both countries, with Britain as something in the form of security wise than their American counterparts. The state of information security is so bad on both sides of the Atlantic, but like the rest of Europe and the world? Is the lack of reported incidents translate data loss on a lack of real events?
In Iceland, for example, reported incidents of data loss in the public or the private sector is very rare. This applies whether the event type, for example, sensitive data is lost, accidentally by a third party or insufficient funds are used to protect valuable information. A possible reason for this lack of public reporting is that the state of IT security is much better in this country than the U.S. or Britain. A more likely explanation is that companies, institutions and employees to discover, not to report these incidents, or they simply go unnoticed.
ENISA, the European Network and Information Security, which recently recommended mandatory loss of information disclosure requirements. ENISA demands governments, organizations and the public to underestimate the dangers of all aspects of IT. Informing the public or at least, occurs Parties loss of data is an important factor in improving awareness of these issues. ENISA, the European Union calls for uniform laws for the response and notification in the event of loss of data to implement. The individual countries within the EU already has similar laws. A new proposal in the UK doing an inadequate protection of data due to damage or loss, an offense punishable by fines.
There is every reason for companies and institutions that are prepared everywhere, even in these areas. Organizations suffer from data loss to lose a lot of confidence to the public. Although business data often have a high direct monetary value. Minimize business with the necessary safety precautions, the risk of data loss and reduce the damage caused in such a case. Practices and internal controls are important in this context, since the vast majority of data loss cases due to negligence or faulty procedures. Monitoring of controls and procedures are also necessary, preferably by external auditors. Laptop and memory encryption and security hardening of remote access systems and e-mail use are examples of simple preventive measures that are also inexpensive. The costs of security, since this is negligible compared to the damage that has caused a great event data loss.