Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

26 July 2009

Senior officer urges less spending on CCTV cameras, more on people

The police are failing to use CCTV to catch as many criminals as they could, a senior officer has told the BBC. Det Ch Insp Mick Neville of the Met police's CCTV unit said most forces do not have systems to retrieve, process and distribute CCTV crime scene images. DCI Neville told the BBC's The World At One and Newsnight that, while his own force had made errors, the picture for the rest of the country "isn't good". "Because we had CCTV first, we made all the mistakes", he said. DCI Neville stated that the mistake was that the money was spent on kit instead of people and processes. He added, "Unless there is a systematic way of gathering CCTV then it will continue not to be as effective as it could be. What I would say, is we've got enough cameras, let's stop now, we don't want any more cameras. Let's invest that money that's available and use it for the training of people, and the processes to make sure whatever we've captured is effectively used." Source: BBC, 20 July 2009. tinyurl.com/m2ksk9

03 July 2009

Have you forgotten your memory stick?

A report into the loss of a memory stick containing data on 6,360 prisoners and ex-prisoners found – predictably – that human error and procedural violation was to blame. The USB stick was being used to back up clinical databases at HMP Preston and was lost on 30 December. The data lost was encrypted but, in a classic example of how IT security actually causes users to bypass defences, the password had been written on a note attached to the misplaced memory stick. Source: BBC, 17 April 2009. tinyurl.com/dl3ceu
Image: http://www.flickr.com/photos/zlatanm/ / CC BY-NC-ND 2.0.

Blame the user? Pah! Bypass the user!

Security is often a hindrance to users, and this means that it is often bypassed. Bruce Schneier, IT security guru, argues that "security systems that require the user to do the right thing are doomed to fail." The solution? Assume uneducated users: to prevent them from changing security settings that would leave them exposed to undue risk, or – even better – to take security out of their hands entirely. Source: Guardian. http://tinyurl.com/bcr7h8