| S | M | T | W | T | F | S |
|---|---|---|---|---|---|---|
| « Feb | ||||||
| 1 | 2 | 3 | ||||
| 4 | 5 | 6 | 7 | 8 | 9 | 10 |
| 11 | 12 | 13 | 14 | 15 | 16 | 17 |
| 18 | 19 | 20 | 21 | 22 | 23 | 24 |
| 25 | 26 | 27 | 28 | 29 | 30 | 31 |
- February 7, 2007: New Techniques for Guarding Financial Data
- February 6, 2007: Increased Scrutiny From Card Associations in 2007
- January 28, 2007: The State of PCI Compliance 2007
- January 23, 2007: Background Checks on IT Personnel
- January 5, 2007: 100 Million Notifications of Data Breaches in US
- December 17, 2006: Inside Jobs: The Risk of Data Breach From Insider Threats
- December 12, 2006: Card Associations Step Up PCI Enforcement
- December 1, 2006: CompTIA Survey Emphasizes Importance of Security Training
- December 1, 2006: CompTIA Survey Emphasizes Importance of Security Training
- November 16, 2006: Average data breach costs $5 million
Credit Card Companies
FAQ
Helpful Sites
CompTIA Survey Emphasizes Importance of Security Training
In the November 20, 2006, edition of eWeek, Brian McCarthy, COO of the Computing Technology Industry Association (CompTIA), reports on results from the 4th annual CompTIA study of information security threats and responses. He states that this year’s study revealed that human error was responsible for nearly 60 percent of data breaches, up from 47 percent last year. Given the role of human error, the shocking revelation of the study is that only 29 percent of the 574 organizations participating in the survey have a required security training program for their IT staff.
With the plethora of news stories about data breaches, it is truly fascinating that such a small percentage of organizations have implemented security training. Mr. McCarthy also points out the value that such proactive training has: “Yet among those organizations that use security training, 84 percent said that it has resulted in a reduced number of major security breaches since implementation; typically through increasing awareness, giving staff the tools to better identify security risks, and improving security measures in general and response time of staff to problems.” You mean the training actually worked???