Coming to grips with IT risk
World-wide business surveys reveal that:
- 85 per cent of those surveyed detected computer security breaches within the previous 12 months;
- 70 per cent cited their internet connection as a frequent point of attack;
- 94 per cent detected computer viruses (85 per cent in 2000);
- over 60 per cent of all email is spam; and
- 30 per cent of information systems accounts are for people who have left the organisation
The risks to nonprofit organisations are just as real.
Connecting computers to the internet allows nonprofits to access a wealth of information and resources. However, it also creates the risk that computers may be tampered with by hackers, or attacked by viruses distributed via email.
It is important to protect yourself against these risks and ensure that your data, including membership and client information, is safe and that your transactions are carried out securely. Otherwise, there is a risk of transactions being intercepted, privacy codes being breached, confidential information being taken or money being stolen.
Remember that information is an asset and therefore it needs to be suitably protected.
The three components of security
There are three core elements to IT security.
- Confidentiality – assuring sensitive data is read only by authorised individuals and is not disclosed to unauthorised individuals or the public.
- Integrity – protecting data or software from improper modification. For example, a virus may infect a program and alter documents created by that program. Data integrity could also be compromised by a disgruntled staff member or volunteer fraudulently changing records.
- Availability – accessibility of IT network, desktop and data resources when authorised users need such access. Availability definitions differ from organisation to organisation and from staff, clients, members, public and other stakeholders but increasingly all groups expect wider availability of these resources. Expectations about websites are that they are available at all times, so if your site is offline for more than a few hours over a weekend it is likely to provoke inconvenience and annoyance.
Four key points
- Building and maintaining trust and credibility with your clients, members, partners and funders is critical to achieving your goals.
- Security is a process, not a project or a product.
- Continuous improvement is the key success factor for good security.
- Initially, security adds to the cost of running your organisation. However, in the long term it could save your credibility, reputation and money.
Many organisations want to expand their use of the internet but are not sure how to do so in a secure way. The following sections of this guide will help you decide which strategies and processes are appropriate for your organisation’s e-security needs.
Tip
While everyone agrees that being safe and secure on the internet is a good thing, online security for many resource-strapped nonprofits is not going to be top of their priority list. But there are some key things that any organisation can do easily and relatively cheaply. These include:
- installing anti-virus software and spyware removal tools;
- installing an internet firewall;
- installing email software with spam filtering capabilities;
- learning a little about spam and online scams and how to avoid them; and
- (importantly) keeping backups.
More information
- See the Australian government booklet Internet Security Essentials for Small Business
- An online training package developed by the Asia Oceania Electronic Marketplace Association, Safety Net Online
, provides self assessment tools, case studies and games to increase awareness of security problems.
- The Internet Industry Association's Security Portal
explains security issues for small to medium organisations. The portal's aim is to build community confidence in using the internet for e-commerce by promoting in all users a culture of security. Have a look at their FAQs
and Fact Sheets
or submit a question to their experts
.
- Also see the Australian government’s brochure and a more detailed booklet Trusting the Internet
.
- See also these e-security tips from the Australian Government’s ‘Trusting the Internet’ fact sheets:
How do I choose the best authentication system?
How do I make sure my digital certificates and keys are secure?
How do I manage my e-security when the service is outsourced?
How do I set up a secure website?
