• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register | Login to Member's Area

 
 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • Information Process Quality Improvement
    19th March - 21st March
    London, United Kingdom
  • Convergence Summit North 2012
    17th April - 18th April
    Manchester, United Kingdom
POPULAR PAPERS
  • Best practices for cloud security by Bloor Research
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Say Again? - "David was a Hebrew king skilled at playing the liar." - From Student Bloopers

PAGE TOOLS
  • Request Reprints
  • Tell A Friend
  • Contact Author
RECENT POSTS
  • Now hold your breath - the Olympic year is nearly upon us
  • BSIMM Version 3 - A Joy to Behold!
  • Secure Systems Development Conference - A Must See!
  • BBC Interviews Nigel Stanley on Phone Hacking
  • BBC Story on Bloor Research into Jihadists use of Smartphones
  • Mobile Phone Hacking at Counter Terrorism Expo, London, April 2011
ADVERTISEMENT
BLOG ARCHIVE
  • December, 2011
  • October, 2011
  • April, 2011
  • March, 2011
  • February, 2011
  • January, 2011
  • December, 2010
  • November, 2010
  • October, 2010
  • September, 2010
  • August, 2010
  • July, 2010
Blogs > Nigel Stanley

Are IT audits like an MOT test for a car?

Nigel Stanley By: Nigel Stanley, Practice Leader - IT Security, Bloor Research
Published: 20th November 2009
Copyright Bloor Research © 2009
Logo for Bloor Research

Here in the UK, after the second world war, lots of people were driving cars which were in pretty bad repair - brakes were poor, lights were damaged and steering was often ropey. This lead to accidents and injuries that could have been prevented. In 1960 the Ministry of Transport introduced a compulsory test, now commonly called the MOT, on all vehicles over 10 years old in an effort to ban the most dangerous cars from the road. Over time the age of annual tests reduced to its current of 3 years and the breadth and depth of the MOT has now expanded to incorporate new technologies such as catalytic convertors.

Is the growth in IT related regulations and compliance requirements following a similar trajectory to the evolution of the MOT test?

All in all we now see far fewer “old bangers” on the road than at any time in the past and I wonder whether we will benefit in seeing fewer data breaches and security lapses as computer systems are put through regular audits or their MOT equivalent.

Of course the mistake many people make when buying a car is to assume that a current MOT certificate is proof that a vehicle is roadworthy. Of course it isn’t - all it means is that at the time of testing the car was able to pass the MOT test.

In a similar way a computer system may pass an audit but very rapidly collapse into a state of non-compliance due to mismanagement. Constant attention to audit and compliance is the only sensible way to manage these needs.

Who knows, with the development of decent compliance and regulations we may see less dangerous IT systems and fewer data loss accidents, crashes and mishaps.

It's food for thought.

Reader Comments

Posted: 20th November 2009 | By The Garland Group :

This is a great analogy. Even if you pass an audit test however, organizations need to remember that security is not point in time.

The messages above were all contributed by IT-Director.com readers. Whilst we take care to remove any posts deemed inappropriate, we can take no responsibility for these comments. If you would like a comment removed please contact our editorial team.

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.



  • Report errors / Make Suggestions
  • | Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761