Security - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.
  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Seven Steps to a Comprehensive Security Strategy

    in Security



    Article Rating:starstarstarstarstar / 1
    Article Views: 3618

      Table of Contents:
    1. Seven Steps to a Comprehensive Security Strategy
    2. Have a 'Sensibility Broker'

    Accenture has been working with companies that are pioneering new approaches to smart IT disaster recovery and through this work has identified seven critical points common to the new security strategies.

    Rate This Article:
    Add This Article To:

    Seven Steps to a Comprehensive Security Strategy - Have a 'Sensibility Broker'


    ( Page 2 of 2 )

     

    No. 4: Have a "sensibility broker" on staff or on retainer

    While it’s unthinkable that a person or organization hired to assess and identify security risks and vulnerabilities would be chastised for doing so, it does happen. Having a neutral go-between that can deliver the results of vulnerability assessments to potentially sensitive administrators and executives objectively is incredibly valuable, says Minyard.

    “It doesn’t happen often, but sometimes folks in charge can be very political and can get extremely defensive about their decisions, and they can be afraid of losing their jobs if certain weaknesses are exposed," he says.

    Tucker says being the neutral, objective party is part of the role companies like his play. He says it’s important to have a third party perform assessments in addition to internal security scans and process reviews to ensure security is matched up with corporate views and policies.

    “For us, as consultants, we are asked to show these guys where their vulnerabilities are; they embrace these results and are thankful that we’ve pointed them out,” Tucker says. In some cases—though Tucker says Patriot hasn’t ever experienced such a situation—it’s possible that individuals who aren’t complying with certain corporate security policies could face repercussions.

    No. 5: Build toward resiliency and robustness

    This includes doing anything and everything possible to ensure continuity in the event of disasters or, Minyard says, new and emerging threats like pandemics.

    “If a pandemic were to hit, you could expect something like a 40 percent absentee rate of employees. You are not going to be able to get your business done and keep running without personnel,” he says.

    Robustness and resiliency preparedness means assessing situations like this and making adjustments in the event of such disasters. For instance, a call center with hundreds of employees seated two feet from each other is rife for the spread of disease, and measures should be put in place to protect employees in the event of infection.

    “People think that security just means putting up e-mail security and firewalls and then you’re OK,” says Tucker. “But it’s important to be able to discuss, plan for and combat emerging and evolving threats.”

    No. 6: De-averaging the data

    Many organizations assess the risk of various threats—hackers, viruses, earthquakes, system failure, etc.—add them together and base their security strategy and risk assessment on the average probability of these events occurring, says Minyard.

    “This is unacceptable. You can't take the mean of all threats and say, ‘Well, the probability across all of these is only 40 percent, so we’re OK,’” he says. Instead, plans and responses must be developed to address each individual threat.

    “One threat, say, viruses or worms, may have a 70 percent chance of occurring, while another, say, an earthquake, may only have a 10 percent chance. Sure, the average of that is 40 percent, but there’s a huge discrepancy there,” he says.

    No. 7: Fix the whole thing, not just the elements

    It’s a pretty common refrain in the security industry, but it bears repeating—take a holistic approach to securing people, technology and processes to ensure comprehensive security.

    “Without looking at all of the components, a security strategy is about as useful as patching one side of a levy,” Minyard says. “You have to see the big picture, see how every application, every process, every employee and every policy is connected together because an impact on any of those causes chain reactions that impact them all.”




     
     
    >>> More Security Articles          >>> More By Sharon Linsenbach
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement