New Survey Measures Computer Security
February 21, 2002 | Read Time: 3 minutes
Slightly more than half of the charities that responded to an online survey on computer-security practices report that they back up their data every day, but 49 percent of the groups say they don’t have a data-recovery plan in place in the event of a serious loss of data.
A new report, “Computer Security Practices in Nonprofit Organizations,” discusses the findings of the survey, which 134 nonprofit organizations completed between December 19, 2001, and January 20, 2002. The organizations vary widely in size, with annual budgets of $2,000 to $50,000,000. Sixty-four percent of the groups report having a budget specifically for information technology. The survey was conducted by NetAction, a San Francisco nonprofit organization that promotes online activism.
Audrie Krause, NetAction’s executive director, says increased news coverage of computer-security issues after the September terrorist attacks made her start to wonder what nonprofit organizations were doing to protect the data on their computer systems, and led the organization to do the survey.
Ms. Krause identifies computer users’ work habits as one of the most important — and most basic — areas that nonprofit organizations need to look at as they think about security issues. Only 36 of the organizations in the survey say that most of their employees shut down their computers when they are away from their desks or when they leave work, and 29 groups say that most do not.
“People don’t understand that if they walk away from their computer, they really need to log off, or somebody can walk up to their computer and look at whatever’s in their hard drive,” says Ms. Krause.
Another area of concern: protecting confidential files from unauthorized use. Seventy-five of the organizations report that they have confidential files stored on computers that are connected to local networks, and 54 have confidential files stored on computers that are connected to the Internet. At the same time, only 15 of the groups use encryption to safeguard any of their sensitive data.
Ms. Krause notes, “In most offices, the human-resources department would know to keep personnel and payroll records in a locked file so that nobody could walk in and get them, but people don’t think about locking them on their computer by encrypting them.”
Although only 36 percent of the organizations that responded to the survey say they have an emergency plan in place to deal with a serious loss of data, Ms. Krause says that she was surprised by the relatively high number of organizations — 64 — that report keeping copies of their data backups in a location other than their offices. “If every computer in your office is destroyed,” she says, “you will still have a backup that you can use to install your data once you get new computers.”
NetAction offers a guide to encryption (http://www.netaction.org/encrypt) and an overview of computer-security basics for nonprofit organizations (http://www.netaction.org/notes/notes76.html) on its Web site, and hopes to provide more in-depth information later this year.
“Computer Security Practices in Nonprofit Organizations” is available on the organization’s Web site at http://netaction.org/security.