Blog

New Report on Data Recovery Operations
January 24, 2012
  As the use of third-party data recovery service providers continues to increase, so does the potential for a data breach to occur during the data recovery process. Permalink

Second Annual Patient Privacy Study Released
December 1, 2011
 Widespread use of mobile devices is putting patient data at risk, according to the latest Ponemon Institute research on healthcare providers' patient privacy practices. Permalink

Best Practices in Data Protection Study Released
November 4, 2011
 Sponsored by McAfee, the Best Practices in Data Protection survey is our latest effort to find out what separates the best organizations from the rest. Permalink

Home » Blog » Susan's Blog » Social Networks Expose Lax Privacy Attitudes » 

RSS Feed

RSS Feed RSS Feed

Social Networks Expose Lax Privacy Attitudes

June 14, 2009

Are online social networking utilities, such as blogs, Facebook, Twitter, LinkedIn, and other popular services changing privacy rules for companies, as this article in Computerworld  suggests, or are the social networking activities of employees simply exposing the poor privacy and security habits of companies?

The Ponemon Institute asked respondents about their social networking habits in our most recent study, Trends in Insider Compliance with Data Security Policies and learned that, while 31% of employees said they access social networking sites while in the workplace, and 34% of those individuals said they have shared information about their place of employment on social networking sites, only 10% said their employer had a written social networking policy.

These findings are consistent with our observation of organizational response to privacy and data security risks in that they show how companies’ policies often lag behind changes to the security environment.

The Ponemon Institute believes that social networking can be a useful and powerful tool for individuals and organizations who consider their strategic value and take thoughtful, necessary precautions to their use.  Without concern for their impact on information security, however, companies that ignore the risks will almost certainly suffer consequences.
 

Posted by Susan Jayson at 5:20 pm


Add Comment (0 comments)