Sunday, August 30, 2009

Why Have a Security Policy?

It is generally impossible to accomplish a complex task without a detailed plan for doing so. A security policy is that plan, and provides for the consistent application of security principles throughout your company. After implementation, it becomes a reference guide when matters of security arise.

A security policy indicates senior management’s commitment to maintaining a secure network, which allows the IT Staff to do a more effective job of securing the company’s information assets. Ultimately, a security policy will reduce your risk of a damaging security incident.

A security policy can provide legal protection to your company. By specifying to your users exactly how they can and cannot use the network, how they should treat confidential information, and the proper use of encryption, you are reducing your liability and exposure in the event of an incident. Further, a security policy provides a written record of your company’s policies if there is ever a question about what is and is not an approved act.

Security policies are often required by third parties as part of their due diligence process. Some examples of these might be auditors, customers, partners, and investors. Companies that do business with your company, particularly those that will be sharing confidential data or connectivity to electronic systems, will be concerned about your security policy.

Lastly, one of the most common reasons why companies create security policies today is to fulfill regulations and standards that relate to security of digital information. A few of the more commonly encountered are:

  • The PCI Data Security Standard (DSS)
  • The Health Insurance Portability and Accountability Act (HIPAA)
  • The Sarbanes-Oxley Act (SOX)
  • Massachusetts 201 CMR 17.00
  • The ISO family of security standards
  • The Graham-Leach-Bliley Act (GLBA)

All these require, in some form, a written IT security policy.

For more information visit www.InstantSecurityPolicy.com

Monday, July 20, 2009

What is an IT Security Policy?

An IT security policy is a strategy for how your company will implement Information Security principles and technologies. It is essentially a business plan that applies only to the Information Security aspects of a business.

A security policy is different from security procedures, in that a policy will provide both high level and specific guidelines on how your company is to protect its data, but will not specify exactly how that is to be accomplished. This provides leeway to choose which security devices and methods are best for your company and budget. A security policy is technology and vendor independent – its intent is to set policy only, which you can then implement in any manner that accomplishes the specified goals.

A security policy should cover all your company’s electronic systems and data. As a general rule, a security policy would not cover hard copies of company data but occasionally some overlap is inevitable. Where the security policy applies to hard copies of information, this must be specifically stated in the applicable policy.

A security policy must specifically accomplish three objectives:

1) It must allow for the confidentiality and privacy of your company’s information.

2) It must provide protection for the integrity of your company’s information.

3) It must provide for the availability of your company’s information.

This is commonly referred to as the “CIA Triad” of Confidentiality, Integrity, and Availability, an approach which is shared by all major security regulations and standards.

For more information visit www.InstantSecurityPolicy.com

Saturday, June 27, 2009

Starting the Process

There is no right or wrong way to begin the process of developing a security policy. No single policy or security strategy will work for every organization. Contrary to what is advertised on the Internet, there is no generic template that will meet every need. A fantastic policy for Company A might be useless to Company B. A security policy must be a custom document that reflects your company’s environment, and meets its specific security needs.

In fact, a useless Security policy is worse than no policy. Companies that boast of Security Policies thicker than a ream of paper are often the ones that have no idea what those policies say. The false sense of security provided by an ineffective policy is dangerous. The point of a Security policy is not to create “shelfware” that will look good in a binder, but rather to create an actionable and realistic policy that your company can use to manage its security practices.

For more information visit www.InstantSecurityPolicy.com