Building an Enterprise Security Program in Ten Simple Steps
The complexity of today's technologies, regulations, business processes, security threats and a multitude of other factors greatly increases the risks faced by businesses today. These tips for building an enterprise security program (ESP) can help.
Step 8: Implement Security Controls
Controls are measures that are put in place to mitigate or eliminate risks. Technical controls are safeguards that are incorporated into computer hardware, software or firmware (e.g., access control mechanisms, identification and authentication mechanisms, encryption methods, intrusion-detection software). Nontechnical controls are management and operational controls such as security policies, operational procedures, and personnel, physical and environmental security.
Controls are usually categorized into preventive controls and detective controls. Preventive controls inhibit attempts to violate security policy, whereas detective controls warn of violations or attempted violations of security policy.
Step 9: Conduct Training
An often ignored step, training employees on security is the key to enforce an ESP. All manner of technology safeguards and security measures do not mean anything if employees are careless about their laptops, connect to insecure networks outside of the workplace, or are unaware of what constitutes suspicious behavior.
Step 10: Conduct Audits
Internal audits ensure that policies and procedures are in place and are effective, controls have been implemented, legal regulations and mandatory compliance requirements are being met, risk is being managed, various security plans are being updated on a regular basis, and training is effective.
External audits are sometimes mandatory to comply with regulations. External audits bring in a neutral third party to provide an unbiased security assessment and recommendations on bridging security gaps.
Making Progress
Information security is no longer a concern of just the IT department. Given the increasing complexity of the ecosystem in which information resides, the criticality of that information to the business, and the growing number of security threats, information security has become the concern of the entire organization. An effective ESP is an organization-wide effort to deal with IT security holistically.
Yesh Dattatreya is the delivery director at MDI Group, and has more than nine years of experience in developing and implementing large transformational IT projects. His most recent project was an IT security consulting project at a large national hospital group.
security



