Sign In

Communications of the ACM

ACM News

Isaca Identifies Top Five Social Media Risks For Business

View as: Print Mobile App Share:

ISACA has named the top five social media risks for business and recommended solutions to help businesses address security, customer service and corporate reputation risks raised by their employees' use of social media—on the job and off.

In a new white paper entitled "Social Media: Business Benefits With Security, Governance and Assurance Perspectives," ISACA, a global association for enterprise governance of information technology (IT), urges organizations to actively address the following potential risks:

  • Viruses/malware
  • Brand hijacking
  • Lack of control over content
  • Unrealistic customer expectations of "Internet-speed" service
  • Non-compliance with record management regulations

Developed by a team of global ISACA experts, the white paper goes beyond the traditional look at social media in the workplace to address employees' use of social media outside of work. It also provides detailed how-to tips for effective social media governance.

"Historically, organizations tried to control risk by denying access to cyberspace, but that won't work with social media," says Robert Stroud, international vice president of ISACA and vice president of IT service management and governance for the service management business unit at CA Technologies. "Companies should embrace it, not block it. But they also need to empower their employees with knowledge to implement sound social media governance."

Since tools like Facebook and Twitter don't require new hardware or software from the IT department, they can be introduced by a business unit, marketing team or individual employees, bypassing the normal safeguards and risk assessment provided by IT, HR and Legal. This issue is reflected in IT department attitudes—62% of respondents to the 2010 ISACA IT Risk/Reward Barometer rated the risk posed by employees visiting social networking sites or checking personal e-mail as medium or high.

When Employees Get Social

Organizations need to consider employee behavior when developing their approach to social media policies and practices. There are four significant risks created when employees use social media, whether they are on the job or off:

Employee Use of Social Media - Risks and Impacts 




Although social media provides a new entry point for technology risks such as malware and viruses, these risks are increased primarily due to lack of employee understanding of "risky behavior." The white paper notes that any strategy to address the potential risks of social media usage should first focus on user behavior.

"The greatest risks posed by social media are all tied to violation of trust," says ISACA Certification Committee member John Pironti, and president of IP Architects LLC. "Social media is built on the assumption of a network of trusted friends and colleagues, which is exploited by social engineering at great cost to companies and everyday users. That is why ongoing education is critical."



No entries found