Implementing a security policy is often viewed as a one-week, one-man project. Decision makers do not view security policies as ongoing projects, such as developing software or maintaining a website. Nor do they feel anybody outside of IT need to be involved. But surprisingly, like many other projects, security policies also evolve and are full of bugs that need fixing. Time is the only factor that allows for such improvements, but time is all too often overlooked.
Common Pitfalls of Policy Enforcement
Companies will be successful in strategically planning out their security policy, but will run into problems when it comes time to enforce it. This can stem from a poorly executed policy in which policy makers did not anticipate the amount of time it would take to properly plan, educate, and train employees.
Just like a company should attempt to motivate all their employees on a new idea or vision, a security policy should be executed in the same manner. People need time to buy into it or else it is bound to fall apart. The most common pitfall in enforcing a security policy is the lack of executives continuously practicing the new policies themselves. A security policy needs to unfold in a top-down direction in order to be effective.
Another common pitfall of enforcing a security policy is the lack of consideration for the employees. Too many decision makers feel that if a new policy is put into place that all employees should fall in line without any complaints. But employees will feel more appreciated and be more willing to comply if their efforts to change are actually recognized and rewarded. Your company may want to consider planning an incentive program to go along with your security policy. If not, at least make it as easy for the users as possible to adopt the new policies.
Structuring Your Policy Roll-Out
During the , security risks within procedures were identified, as well as a plan for how these risks will be handled. The improvements that need to be made should be listed in order of importance.
Ths list shown below can be utilized as a cheat sheet to help categorize the procedures into different implementation groups. Each change should be categorized as having high or low user impact (UI), and having high or low security impact (SI).
For example, say you want your IT administrator to change the default passwords every month, as part of your new security policy. That would not impact the average user much, but it would be a high security benefit. Therefore, it would be placed in the first group.
1) LOW UI, HIGH SI - Has minimal user impact so changes can be easy and immediate
(ex: Changing default passwords every month)
2) HIGH UI, HIGH SI - Requires education and training with a high impact on security
(ex: Deployment of new security software such as encryption)
3) HIGH UI, LOW SI - Requires education and training with only a low impact on security (
ex: Holding meetings to educate users about new security policies)
4) LOW UI, LOW SI - Can be deferred until after completion of other solutions
(ex: Moving one security solution that works in one dept. to another dept.)
(Go here to view this list as a matrix: )
Prioritizing Your Policy Changes
The quadrants are numbered to specify which changes should be implemented first. Keep in mind that although activities in quadrants 2 and 3 require more time for a learning curve, the education and training can take place at the same time that changes in quadrant 1 are being made. Changes placed in quadrant 4 are not as urgent and do not provide much improvement to existing security and therefore are usually deferred to a later time.
The Move toward Policy
Now is the time for companies to start taking security seriously. Whether it's an insider who steals customer records from Fidelity National Information Services or a hacker who breaches the information network of Ohio State University, stricter policies will help to prevent such incidents, both intentional and accidental.
Resources and tools have become more readily available than ever before, so the process does not need to be performed alone. There are companies out there who can meet your needs once you've identified them. If the tips provided in this article are applied in the planning process of your company's security policy, it should lead you on your way to creating a more safe and secure environment for your employees and your customers.
It Security Policy Template
Locating sensitive files is one of the most important tasks of computer security audit and forensic data recovery. Security experts need to make sure that sensitive files are not available for third-parties and are kept in a secure way. Computer forensics specialists need to find these files for research purposes. Another problem is possible security leakages that security expert should prevent.
What is the best way to securely manage files. The most important aspect is clear understanding of tasks that your company face. First, it's necessary to elaborate a security policy.
Security policy is a set of documents that employees of your company can follow to achieve company security-related goals. This document must describe in what secure way can information be kept and exchanged. How strong should be passwords, what encryption should be applied to email exchange, who have an access to a certain data.
Security policy should be supported with certain security software, that allows to manage information in a secure way. First, you need to have a secure data storage. It must provide a secure environment for keeping files as well as necessary backup capabilities. If you are running a small business company, then it would be enough an encrypted partition on your hard disk. Large organization prefer to establish a access level control with necessary rights to access and modify information.
If you have a good security policy then the next step is to ensure that your employees follow requirements of security policy. For instance, one of the most important requirements is using strong passwords, that must be changed often. Use password audit software to ensure users don't use too simple passwords, which are easily recoverable using dictionary based attack. Do a password security audit for specific files, for users system and network accounts.
If files are managed securely enough? Track all possible ways how user can access, modify and get a copy of file. It can be sent by email, it can be copied to flash device or it can be simply access by unauthorized person. Consider using software that logs file operations and represent easy-readable report. This is a one of the measure that allows to find and prevent possible data leakages.
You as a business manage might also wish to track emails and web-sites that your employees read and access. Some business really require this, but make sure it's allowed by your privacy statement, that you and your employees know about.
One the most challenging issues is using a portable devices with large capacity, such as flash and sd cards. It's possible to regulate access to computer using these devices with third-party software too.
The trust is that it's not really possible to protect yourself from all kind of attacks, so consider hiring a security auditor who will regularly check your company for possible security problems. And it's a good idea to provide this specialist with company security policy and records that might be analyzed to find possible data leakages.
Both Veronica Mun & Sam are contributors for EditorialToday. The above articles have been edited for relevancy and timeliness. All write-ups, reviews, tips and guides published by EditorialToday.com and its partners or affiliates are for informational purposes only. They should not be used for any legal or any other type of advice. We do not endorse any author, contributor, writer or article posted by our team.
Veronica Mun has sinced written about articles on various topics from Business Intelligence, Phishing and Software. End Notes:1) ?You've Got a Security Policy. Now What?? Implement & Integrate. 3 Jan. 2007: 4.2) Ibid.. Veronica Mun's top article generates over 4400 views. to your Favourites.
Sam has sinced written about articles on various topics from Software, Management and Nokia Phones. %author_bio%. Sam's top article generates over 49500 views. to your Favourites.
Blood Pressure Monitor Home Use If your blood pressure is under control, you may need only check it at home a few times a month but remember that home monitoring is not a substitute for visits to your doctor