Research Focus

IT Struggling Over Security, Compliance

  • By Jabulani Leffall
  • 05/15/08

IT pros are having a hard time balancing security, software patch management and IT auditing with a host of other duties, according to a survey released Monday by Shavlik Technologies.

The St. Paul, MN-based security consultancy gathered its findings from attendees at the recent RSA Conference and Infosecurity Europe events, both in April.

In summary, the group found that the No. 1 difficulty among IT pros was finding an all-encompassing approach to tackle vulnerabilities, protect data and meet compliance objectives--all while doing that pesky thing: their actual jobs.

"[What we've found is] despite efforts to apply various technologies, companies continue to struggle with efforts to manage and close vulnerability gaps, while concerns over regulatory compliance are driving them to look for more ways to simplify through automation," wrote Mark Shavlik, founder and chief executive of Shavlik, in an e-mail Monday.

Mark Shavlik added that, generally speaking, "organizations struggle to manage their security and compliance needs which leaves them open to attack or the discovery of a weak link by an auditor."

The company said that its survey of 491 IT pros, which comprised attendees of both the San Francisco and London meetings, identified the following as the top three priorities:

  • Data protection, integrity and information leakage prevention garnered the vote of 53.2 percent of respondents.

  • "Internal network security" considerations were the second-most visible priority, with 51.8 percent of respondents.

  • In third place were internal IT policy and procedure alignments and regulatory concerns -- the bane of many systems or security administrators' existence--such as Sarbanes-Oxley, HIPAA, PCI DSS and others. This clocked in at 43.8 percent.

Rounding out the other issues deemed "significant" were patch management, something IT pros in the Windows Enterprise space will have to deal with Tuesday, and the fortitude of programs and applications housed on virtual machines.

Comments

Add your Comment

Your Name:(optional)
Your Email:(optional)
Your Location:(optional)
Comment:
Please type the letters/numbers you see above