IT-Analysis.com
IT-Analysis.com Logo
Enterprise SME Business Issues Technology Services Channels
Module Header
Peter AbrahamsAbrahams Accessibility
Peter Abrahams
7th February - Android: Ice Cream Sandwich Accessibliity
David NorfolkThe Norfolk Punt
David Norfolk
7th February - BCS CMSG Conference 2012
Fern HalperFern Halper
Dr Fern Halper
31st January - Four Vendor Views on Big Data and Big Data Analytics: IBM
Fran HowarthBloor Security Blog
Fran Howarth
30th January - Getting ahead in the cloud
Philip HowardBloor IM Blog
Philip Howard
25th January - Cassandra and Hadoop
Blogs > Nigel Stanley
Are IT audits like an MOT test for a car?
Nigel Stanley By: Nigel Stanley, Practice Leader - IT Security, Bloor Research
Published: 20th November 2009
Copyright Bloor Research © 2009
Logo for Bloor Research

Here in the UK, after the second world war, lots of people were driving cars which were in pretty bad repair - brakes were poor, lights were damaged and steering was often ropey. This lead to accidents and injuries that could have been prevented. In 1960 the Ministry of Transport introduced a compulsory test, now commonly called the MOT, on all vehicles over 10 years old in an effort to ban the most dangerous cars from the road. Over time the age of annual tests reduced to its current of 3 years and the breadth and depth of the MOT has now expanded to incorporate new technologies such as catalytic convertors.

Is the growth in IT related regulations and compliance requirements following a similar trajectory to the evolution of the MOT test?

All in all we now see far fewer “old bangers” on the road than at any time in the past and I wonder whether we will benefit in seeing fewer data breaches and security lapses as computer systems are put through regular audits or their MOT equivalent.

Of course the mistake many people make when buying a car is to assume that a current MOT certificate is proof that a vehicle is roadworthy. Of course it isn’t - all it means is that at the time of testing the car was able to pass the MOT test.

In a similar way a computer system may pass an audit but very rapidly collapse into a state of non-compliance due to mismanagement. Constant attention to audit and compliance is the only sensible way to manage these needs.

Who knows, with the development of decent compliance and regulations we may see less dangerous IT systems and fewer data loss accidents, crashes and mishaps.

It's food for thought.

Reader Comments

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

20th November 2009: 'The Garland Group' said:

This is a great analogy. Even if you pass an audit test however, organizations need to remember that security is not point in time.

Reply to The Garland Group?

Advertisement



Published by: IT Analysis Communications Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761
Email: