The security threat environment is becoming more and more complicated and companies – both large and small – are going to be held to even more strict compliance standards.
Every organization has considerably more work than resources to accomplish it all, so prioritization is important to make sure the most critical risks are being addressed. Companies have usually invested between 6 and 10 percent of their IT spend in security, and many of them are looking for a uniform way to measure success.
Recently, nCircle, a provider of information risk and security performance management solutions, published the results of a survey of 241 attendees of the Black Hat USA 2012 security conference in Las Vegas, Nevada.
In the survey, the company asked the respondents “Will government regulation improve information security for critical infrastructure?” Sixty percent of them responded “no.”
The U.S. Critical Infrastructure (CIP) program identified important physical and virtual systems, so important to the United States that the failure of such systems and assets would have devastating effect on security, national economic security and national public health or safety, the company stated in a news release.
“It’s not surprising that IT security professionals think government regulation won’t improve critical infrastructure security as Congress doesn’t seem to have the technical expertise to craft laws that address critical infrastructure security,” said Lamar Bailey, director of security research and development for nCircle. “While the U.S. government has some outstanding security researchers, they are confined to the DoD and other cabinet agencies where the focus is on gathering data, not sharing it.”
nCircle recently announced the results of the nCircle 2012 Cloud Security Trend Study. Highlights from the study stated that cloud computing continues to be a top security concern for the third year in a row, in spite of the changing threat landscape. Only 7 percent of respondents outsource more than 30 percent of their organizations' infrastructure to the cloud.
Want to learn more about the latest in communications and technology? Then be sure to attend ITEXPO West 2012, taking place Oct. 2-5, in Austin, TX. ITEXPO (News - Alert) offers an educational program to help corporate decision makers select the right IP-based voice, video, fax and unified communications solutions to improve their operations. It's also where service providers learn how to profitably roll out the services their subscribers are clamoring for – and where resellers can learn about new growth opportunities. For more information on registering for ITEXPO click here.
Stay in touch with everything happening at ITEXPO. Follow us on Twitter.