SAN FRANCISCO -- With the release of a new study, "1998 Information Security Staffing Levels and the Standard of Due Care," the Computer Security Institute (CSI), in collaboration with author and consultant Charles Cresson Wood of Baseline Software (www.baselinesoft.com), have provided information security professionals with another invaluable tool. The study's findings offer the hard evidence needed to determine whether or not an organization's staffing levels are in keeping with industry standards.
Highlights of the study include the following:
- Information security staff levels as a percentage of total workers have increased 49% since last year.
- Respondents expect information security staffing levels to increase 15% in the next year.
- Respondents expect the total budget for information security to grow 20% in the next year.
- Percentage of work done by external firms increased this year to 7% of the total workforce (external and internal).
Charles Cresson Woods' management summary of the study can be accessed via the World Wide Web at both http//www.gocsi.com or http://www.baselinesoft.com.
The Spring '98 issue of the quarterly Computer Security Journal offers insights on other important aspects of building a successful information protection program. For example, in "How to select security solutions for Web-enabled enterprises," Tom Lister of DASCOM (www.DASCOM.com) provides some insights on the stages of intranet and extranet development, as well as a checklist of practical questions to ask in evaluating security solutions for such web-based information infrastructures.
In "How to build an information classification program," Tom Peltier of Cybersafe (www.cybersafe.com) outlines the steps you should take to implement an enterprise-wide data classification program and provides examples of data classification schemes, a set of data handling matrices and even a data classification worksheet.
The quarterly Computer Security Journal is one of the many benefits of membership in CSI. Non-members can purchase individual copies of the Computer Security Journal for $25.00. To order, click here.
For more information on the many benefits of membership in the Computer Security Institute, call 415-947-6320 or visit http://www.gocsi.com.
Computer Security Institute is the leading international membership organization dedicated to assisting information security professionals in protecting the information assets of their organizations. Since 1974, CSI has been the world's leading proponent of information security--aggressively advocating the critical importance of protecting information assets. CSI provides a wide variety of publications and educational programs. For more information on other CSI publications, membership or training please contact CSI at 415-947-6320, fax 415-947-6023, email: rrichardson@cmp.com.
Charles Cresson Wood, CISA, CISSP, is an independent information security consultant based in Sausalito, CA. He is the recipient of the 1996 CSI Lifetime Achievement Award. The Fifth Edition of his third book, entitled Information Security Policies Made Easy, contains 730+ already written policies in both floppy and hardcopy form (published by Baseline Software, phone 415-332-7763, fax 415-332-8032).