Video | Agriculture | Confidence | Economy | Energy | Employment | Finance | Media | Property | RBNZ | SciTech | SOEs | Tax | Telecoms | Tourism | Transport | More Categories

 


IT practices inadequate for forensic evidence

Wednesday 26 September 2007


IT management practices inadequate to preserve forensic evidence


The second annual New Zealand Computer Crime and Security Survey has revealed New Zealand organisations are ill-equipped to preserve computer forensic evidence.

The University of Otago conducted survey – which aims to raise the level of security awareness and determine the scope of computer crime in New Zealand – has found that IT management practices are inadequate when it comes to the preservation of forensic evidence that could lead to criminal convictions for computer hackers or fraudulent employees.

University of Otago researcher KJ Spike Quinn is concerned that New Zealand organisations do not appreciate the full seriousness of computer crime and associated consequences – both financially and with regard to the reputation of an organisation.

“Management of forensic capability is woefully short of ensuring admissibility of evidence in court. Having a suitably trained person first on the scene makes all the difference in whether a prosecution is successful,” Mr Quinn says.

Most organisations reported having the basic protection, such as antivirus and firewall technologies in place, but only 7 per cent of respondents had a forensically-trained first responder.

When an incident or intrusion occurred, 40 per cent reported it to management and 30 per cent did their best to patch security holes in network systems. Only 16 per cent reported intrusions to law enforcement. A third of the respondents who did not report intrusions to law enforcement were unaware of law enforcement interest.

Sixty-six per cent of New Zealand organisations invest of up to 5 per cent of their IT budget on security issues, compared to the 43 per cent Australian and 55 per cent United States figures.

“This investment figure initially sounds good, but AusCERT found in its 2006 report that 51 per cent of respondents considered an investment of up to 5 per cent to be inadequate. We need to be investing more now to be protected in the long term,” Mr Quinn says.

Only 5 per cent of New Zealand organisations spent more than 10 per cent of their IT budget on security, compared with 13 per cent in the United States and 14 per cent in Australia.

“These figures, coupled with the forensic readiness finding, predict a rise in failed prosecutions. The implementation of basic policies and procedures, plus basic security training, need to be adopted more widely. If there’s no training and no procedure laid down, you can’t expect staff to act appropriately,” Mr Quinn says.

Centre for Critical Infrastructure Protection Managing Director Richard Byfield says security threats and risks continue to increase and evolve to defeat our best defences.

“Key cyber threats include those from foreign intelligence services, organised crime syndicates, political activists, individuals acting alone, botnets and spam. As the tools and techniques of the adversaries improve, so must our ability to detect and deter these threats.”

Although most organisations surveyed had basic security features, technology solutions alone are not enough and organisations need to build a culture of cyber security, Mr Byfield says.

“People are a key component to raising the security posture of an organisation, but they need to be supported by clear and practical policy and procedures. On-going cyber security education and awareness initiatives are essential to ensuring that people are sensitised to the threats,” Mr Byfield says.

The survey also found that only 22 per cent of New Zealand respondents reported unauthorised use of computer resources, whereas the US figure was 52 per cent. This is possibly because New Zealand has greater access to computers and the Internet away from work.

The 2006 survey considered prevalence of security incidents, percentage of information technology department budget spent on security issues, use of cyber-security incident insurance, and intruder detection systems and other technologies, as well as popularity of workstation operating systems. Survey results are based on the responses of 113 computer security practitioners in New Zealand manufacturing, governmental, financial and medical organisations, and tertiary education providers regarding the 2005 calendar year.


ENDS

 
 
Business Headlines | Sci-Tech Headlines

Gordon Campbell: On John Key’s Agenda For The Nation

There seemed to be three main components to John Key’s speech :

a) tax cuts largely paid for by a hike in GST
b) mining in national parks and on conservation land, while building more roads.
c) giving firms easier access to the r&d from Crown Research Institutes, so that business can continue to get the taxpayer to pick up the tab for the research that keeps them competitive.

After all, corporate welfare is always such a blessed thing – its only social welfare that corrodes enterprise and ambition. More>>

 

I Want A New Drug: Paradex And Capadex To Be Withdrawn From NZ

All medicines containing dextropropoxyphene will be withdrawn from the New Zealand market after a review of the safety and efficacy of these medicines showed that their risks outweighed their possible benefits. More>>

Keith Rankin: Personal Income Tax Reform In New Zealand

While I agree that the system is far from perfect, few of us understand the basics of our present personal tax scales, and workable suggestions of alternatives are few and far between. More>>

ALSO:

Q+A Transcript: Catching Australia By 2025 LOL

- Bollard dismisses government’s aim of catching Australian incomes by 2025: “I don’t think we can catch up with Australia”
- Bollard says New Zealand should aim to benefit from the “crumbs [that] come off the Australian table”
- New Zealand recovery from recession “still fragile” More>>

ALSO:

DOC vs. National: Government Pressure To Privatise Mackenzie

Independent conservation organisation Forest & Bird has obtained documents under the Official Information Act that reveal the Government is stopping the Department of Conservation (DOC) from trying to protect the Mackenzie Basin from destruction by intensive irrigation. More >>

ALSO:

Employment: NZ Jobless Rate Jumps To 7.3% Sending Kiwi Down

New Zealand’s unemployment rate surged more than expected in the fourth quarter to the highest in more than a decade, stoking speculation the central bank won’t rush to raise interest rates. More>>

ALSO:

Media: 3 News Programmes Win "Key" Demographic

3 News , Campbell Live and Nightline all had strong nationwide wins against competing shows in the all important 18-49 demographic in January, retaining the competitive lead they held in December. More>>

Crazy? Yes! Dumb? No! Mint Chicks Join New Model For Music Sales

Wellington-based global internet entrepreneur WebFund is backing what it hopes will be a new way to make money in the cruel and unusual world of digital music sales. More>>

ALSO:

Conservation: Signing South Pacific Fisheries Agreement Welcomed

The Environment and Conservation Organisations (ECO) today welcomed New Zealand signing the South Pacific regional fisheries management agreement. ECO Co-chairperson, Cath Wallace, said the agreement was essential for the management of pelagic and bottom fisheries in the South Pacific, including orange roughy and jack mackerel. More >>

MOST READ HEADLINES

More RSS  RSS
 
 
 
powered by newsagent
NZ independent news