Manager’s guide: Tailor-made security policy

August 2014 Information Security

With the never ending number of security threats to business information it is imperative that managers take the initiative to establish working and evolving security policies that protect the business and its assets. As the popular saying goes, “prevention is better than cure” and nothing could be more pertinent to the importance of having a security policy in a business. But where to start?

Gregory Anderson, country manager at Trend Micro South Africa.
Gregory Anderson, country manager at Trend Micro South Africa.

Establish security threats to your business

In order to face up to threats you need to be savvy about them. With today’s identity theft, spam and spyware – software that secretly monitors a user’s activity with the intention of information theft – you may be surprised by how fundamental some of the biggest threats are. IT threats are constantly evolving, which is why it’s important that your security policy and plans do the same. Keep your system flexible enough to meet not only present but future problems as well.

Bear in mind the legislation involved in your IT responsibilities, privacy and electronic communication responsibilities and your treatment of employees as well as the regulations from the European Commission. Also remember that every business has different information security threats, some unique and some universal, the manager’s job is to account for all existing and possible threats to security and tailor a security policy that will counteract them.

Establishing a security policy

All-encompassing IT security is built on the foundation laid by a company security policy. A good place to start when creating a security policy for your business is with the risk analysis of what threats are posed to your business. A layered approach is necessary to cover all bases starting with a mission statement from a manager and moving into physical devices, roles and responsibilities of staff, including references to acceptable use and how security breaches will be dealt with. This is also a great place to host your business continuity and disaster recovery plans.

Next, you need to sort out what to include in the security policy. A clear explanation of the purpose of the policy, its ultimate goals and strategic importance of information security to the business should be the first thing on the agenda.

Make a list of the training available to employees to help them better understand information and security risks. It is imperative to give the policy authority by including a statement of support from senior management demonstrating a commitment to information security. Remember that every business will have different security needs so the most important things to include in the security policy will differ from business to business.

Protecting your IT assets

IT asset protection starts with providing your staff with clearly communicated guidelines on acceptable use, confidentiality and standards for security measures. An explanation of what is and isn’t allowed on company time and company computers and outlines the repercussions for disregarding the policy ensures that staff do not expose the company to malware, share confidential information over the Internet or take sensitive information off-site on laptops or USB drives.

Staff will understand the importance of an acceptable use policy as long as it strikes a balance between pragmatism and control and the company is clear about the risks it is trying to avoid. In order to weave acceptable policy usage into the culture of the company tie them into employee contracts and disciplinary procedures.

A functioning security policy

Think of your company security policy as a never ending work in progress that you definitely shouldn’t leave collecting dust. For a security policy to be meaningful it needs to be a living, breathing document that management and staff access and refer to. The fundamental elements of a security policy are management’s visible commitment to it, employee awareness and education on the security policy as well as ensuring that the policy remains relevant and up to date.

After you have put together the company security policy you need to determine how you will administer security which will come down to a mixture of people, policies, processes and technology all of which play a critical part in ensuring overall security. If businesses are small it is unnecessary to take on additional staff to administer IT security systems, you can rather give the responsibility to existing managers. However, if an external consultant is called upon to set up the security policy, ensure that they report back to management at every step as you shouldn’t leave it to an outsider to keep you safe.

As a manager it is your responsibility to ensure that your staff and colleagues understand the importance of the security policy. With the number of IT security threats increasing and strengthening constantly it is important to be aware that your business is as viable a target as anyone else’s. Breaches to security are no longer a question of ‘if’ but ‘when’ and if you have tailored a security policy to your business you and your staff will be prepared to handle inevitable breaches of security.

For more information, visit www.trendmicro.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Managed security solutions for organisations of all sizes
Information Security News & Events
Cyber attackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...
Data resilience at VeeamON
Technews Publishing SMART Security Solutions Infrastructure Information Security
SMART Security Solutions attended the VeeamON Tour in Johannesburg in August to learn more about data resilience and Veeam’s initiatives to enhance data protection, both on-site and in the cloud.

Read more...
Troye exposes the Entra ID backup blind spot
Information Security Infrastructure
If you trust Microsoft to protect your identity, think again. Many organisations naively believe that Microsoft’s shared responsibility model covers Microsoft Entra?ID – formerly Azure AD – but it does not.

Read more...
Secure data protection without hardware lock-in
Infrastructure Information Security News & Events
New Veeam Software Appliance empowers IT teams to achieve instant protection with Veeam’s fully preconfigured, software-only appliance, delivering enterprise-ready simplified deployment and operational efficiency, robust cyber resilience.

Read more...
Check Point launches open, vendor-neutral MDR services
Information Security News & Events Products & Solutions
New Check Point MDR 360° and MXDR 360° offerings deliver 24/7 managed continuous threat monitoring protection across endpoints, cloud and network environments with built-in identity threat detection and 160+ integrations across hybrid, multi-vendor environments.

Read more...
Credential theft surges in South Africa
NEC XON Information Security
NEC XON issues a critical cybersecurity warning about the dual threat of massive credential theft and AI-powered cyberattacks sweeping across the region, with an increasing number of incidents and evolving threat tactics.

Read more...
Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.