Monday, November 09, 2009

Information Security Tip #3: Procedures

Policies and procedures help you meet your obligation to your customers, affiliates, and employees. Protect your electronic information with these simple steps:
  • Physical security. Network defenses can be critical, but when it comes to protecting personal information, don’t forget physical security. Ensure access to network servers is restricted to authorized personnel.
  • Encryption. Use encryption to protect sensitive data such as credit card numbers, social security numbers, driver’s license numbers, etc.
  • Viruses. Viruses, spyware, and other malware can compromise your systems and your data. Ensure your anti-virus and anti-spyware software is updated on a regular basis.
  • Passwords. Most organizations use an ID and password to grant access to your data. Ensure your passwords are long and complex and changed on a regular basis.
  • Education. Remind your employees that electronic security is everybody’s business. Hackers certainly pose a threat, but sometimes the biggest risk to a company’s security is an employee who hasn’t learned the basics.
  • Access. Provide access to sensitive information only on a “need to know” basis. Have a procedure in place for making sure that workers who leave your employ or move to another part of the business no longer have access to off-limits information.
  • Detection. Intrusion detection systems can alert you to breaches in your network security. IT should monitor incoming and outgoing traffic for higher-than-average use at unusual times of the day.
  • Patching. Check expert resources like www.sans.org and your software vendors’ websites for alerts about the latest vulnerabilities and vendor-approved patches.
  • Providers. Ensure security practices of your contractors and service providers. Before outsourcing business functions, ensure agreements define security requirements.
  • Documentation. Organization policies give direction and guidance but generally lack sufficient details to describe how things should be done. By documenting your detailed procedures, your organization can ensures consistent and sustainable protection of your information assets.
Not all risks are created equal and risk assessments help firms reduce their costs while increasing protection of their “information assets”.

Labels: , ,

Tuesday, December 04, 2007

Information Security Policy

Security Policies. Policies represent the corporate philosophy of an organization. They provide management the direction and support needed to perform their day-to-day duties. In the case of information security, an information security policy helps provide direction in accordance with business requirements, standards, laws, and regulations.

Policies should be established in line with business objectives. For example, management demonstrates support for and commitment to information security through the issuance and maintenance of an information security policy.

Leading organizations use an information security policy to define information security and establish the framework for setting control objectives within an organization. Policies help organizations ensure that preventative, detective, and corrective controls are in place and operating as desired.

Labels: , , ,

Tuesday, June 05, 2007

Policies Manage Your Risks

Policies help organizations manage risks. By reviewing business requirements and anticipated future growth plans, organizations can identify and prepare policies that are aligned with the organization's goals and objectives.

Policies often consist of the following:


  • Policy – the rules and requirements for risk management and continuing business operations.

  • Standards – detailed networking and security technologies for protecting information systems.

  • Guidelines – system or topic related recommendations and best practices.

  • Procedures – details to implement standards and guidelines, guides for installing software, securing facilities, documenting security breaches, etc.


In some instances, policies can conflict with each other. In these circumstances, a steering committee can address policy conflicts and identify appropriate compromises and alternative solutions.


If your organization lacks policies, policy templates provide a jump start and help you manage your risks. More information on policy templates is available at Altius IT.

Labels: , ,

Wednesday, April 05, 2006

Security Tip #10 - Don't Risk Client Trust

Don’t risk losing your clients’ trust in you. Protect your IT systems with security policies and procedures. You'll protect your information assets and your valuable image and reputation.

By not having sound policies and procedures, many organizations face the following risks:


  • Loss of data integrity and client trust in you


  • Your clients incur lower levels of service due to untimely IT operations


  • You experience increased management accountability due to loss of adequate controls


  • You incur increased costs due to systems that are not always available

Security policies and procedures can help you maintain client confidentiality. By implementing effective policies and procedures, client trust is maintained even while security threats are increasing at an alarming rate.

Many critical business processes and client interactions are now automated to the point where the importance of security readiness has risen exponentially. Don’t count on firewalls and passwords to protect your valuable information assets. Security policies help you manage your risks and are your key to maintaining client trust.

Find out why you need a managed approach to security instead of the ad-hoc approach that leaves many organizations vulnerable.

Labels: , , ,