Contact
QR code for the current URL

Story Box-ID: 214366

ENISA - European Network and Information Security Agency P.O. Box 1309 71001 Heraklion, Crete, Greece http://www.enisa.europa.eu
Contact Mr Ulf Bergström +30 694 846 0143
Company logo of ENISA - European Network and Information Security Agency
ENISA - European Network and Information Security Agency

The Scandinavian approach to Awareness Raising: ENISA survey reveals how 100 European Local Governments 'can do more'

The EU Agency ENISA presents the results of a survey of 100 Scandinavian local government's data management efforts within health, hospital, regional development, education and public transportation services

(PresseBox) (Heraklion, Crete, )
One of the most common privacy infringements is wrongful access to a patient's sensitive data. Health care services, hospitals, public transport and education systems at regional and municipal level alike all treat personal data, with inherit risks. The study portrays how 110 regions and municipalities, responsible for the services above in the three Scandinavian countries, Denmark, Norway and Sweden are working on the secure management of such information. The conclusion is that not enough attention is paid to raising awareness among staff, but generally the authorities do well in terms of technical systems and policies.

A total of 110 public bodies, (of which 97 municipalities and 13 regions) responded to a 54 questions-survey. The responses are consolidated and analyzed in a Scandinavian perspective. The survey focused on four areas: 1. Managing IT Risks, 2. Information Security Management, 3. Policy Enforcement, 4. Awareness Management- securing employee compliance and attention to policies, roles and responsibilities. Overall, the survey shows that the bodies have focused on: 1. Risks, 2. Goals for information security (policy), 3. Creating a framework for information security management. 4. With regard to the staff awareness, the survey confirms that:

- Rights, obligations and sanctions are typically described by the bodies
- Staff is to some extent given access to security rules
- Little is done to provide knowledge through further training
- Knowledge of rules is rarely followed-up
- Undesired behaviour is rarely followed-up

The Executive Director of ENISA, Mr. Andrea Pirotti observed: "This report underlines the fact that staff must first be aware of a) what data has to be protected and b) why, it if they are to comply with security rules. The situation is good, but not good enough: more still has to be done."

The report is the result of the kind support by the ENISA Awareness Raising (AR) Community.
For further information: http://www.enisa.europa.eu/

ENISA - European Network and Information Security Agency

The European Network and Information Security Agency (ENISA) is an agency of the European Union. ENISA was created in 2004 by EU Regulation No 460/2004 and is fully operational since September 1st, 2005. It has its seat in Heraklion, Crete (Greece). The objective of ENISA is to improve network and information security in the European Union. The agency has to contribute to the development of a culture of network and information security for the benefit of the citizens, consumers, enterprises and public sector organisations of the European Union, and consequently will contribute to the smooth functioning of the EU Internal Market. ENISA assists the Commission, the Member States and, consequently, the business community in meeting the requirements of network and information security, including present and future Community legislation. ENISA ultimately strives to serve as a centre of expertise for both Member States and EU Institutions to seek advice on matters related to network and information security.

The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.
Important note:

Systematic data storage as well as the use of even parts of this database are only permitted with the written consent of unn | UNITED NEWS NETWORK GmbH.

unn | UNITED NEWS NETWORK GmbH 2002–2024, All rights reserved

The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.