Manager’s guide: Tailor-made security policy

August 2014 Information Security

With the never ending number of security threats to business information it is imperative that managers take the initiative to establish working and evolving security policies that protect the business and its assets. As the popular saying goes, “prevention is better than cure” and nothing could be more pertinent to the importance of having a security policy in a business. But where to start?

Gregory Anderson, country manager at Trend Micro South Africa.
Gregory Anderson, country manager at Trend Micro South Africa.

Establish security threats to your business

In order to face up to threats you need to be savvy about them. With today’s identity theft, spam and spyware – software that secretly monitors a user’s activity with the intention of information theft – you may be surprised by how fundamental some of the biggest threats are. IT threats are constantly evolving, which is why it’s important that your security policy and plans do the same. Keep your system flexible enough to meet not only present but future problems as well.

Bear in mind the legislation involved in your IT responsibilities, privacy and electronic communication responsibilities and your treatment of employees as well as the regulations from the European Commission. Also remember that every business has different information security threats, some unique and some universal, the manager’s job is to account for all existing and possible threats to security and tailor a security policy that will counteract them.

Establishing a security policy

All-encompassing IT security is built on the foundation laid by a company security policy. A good place to start when creating a security policy for your business is with the risk analysis of what threats are posed to your business. A layered approach is necessary to cover all bases starting with a mission statement from a manager and moving into physical devices, roles and responsibilities of staff, including references to acceptable use and how security breaches will be dealt with. This is also a great place to host your business continuity and disaster recovery plans.

Next, you need to sort out what to include in the security policy. A clear explanation of the purpose of the policy, its ultimate goals and strategic importance of information security to the business should be the first thing on the agenda.

Make a list of the training available to employees to help them better understand information and security risks. It is imperative to give the policy authority by including a statement of support from senior management demonstrating a commitment to information security. Remember that every business will have different security needs so the most important things to include in the security policy will differ from business to business.

Protecting your IT assets

IT asset protection starts with providing your staff with clearly communicated guidelines on acceptable use, confidentiality and standards for security measures. An explanation of what is and isn’t allowed on company time and company computers and outlines the repercussions for disregarding the policy ensures that staff do not expose the company to malware, share confidential information over the Internet or take sensitive information off-site on laptops or USB drives.

Staff will understand the importance of an acceptable use policy as long as it strikes a balance between pragmatism and control and the company is clear about the risks it is trying to avoid. In order to weave acceptable policy usage into the culture of the company tie them into employee contracts and disciplinary procedures.

A functioning security policy

Think of your company security policy as a never ending work in progress that you definitely shouldn’t leave collecting dust. For a security policy to be meaningful it needs to be a living, breathing document that management and staff access and refer to. The fundamental elements of a security policy are management’s visible commitment to it, employee awareness and education on the security policy as well as ensuring that the policy remains relevant and up to date.

After you have put together the company security policy you need to determine how you will administer security which will come down to a mixture of people, policies, processes and technology all of which play a critical part in ensuring overall security. If businesses are small it is unnecessary to take on additional staff to administer IT security systems, you can rather give the responsibility to existing managers. However, if an external consultant is called upon to set up the security policy, ensure that they report back to management at every step as you shouldn’t leave it to an outsider to keep you safe.

As a manager it is your responsibility to ensure that your staff and colleagues understand the importance of the security policy. With the number of IT security threats increasing and strengthening constantly it is important to be aware that your business is as viable a target as anyone else’s. Breaches to security are no longer a question of ‘if’ but ‘when’ and if you have tailored a security policy to your business you and your staff will be prepared to handle inevitable breaches of security.

For more information, visit www.trendmicro.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Integrated security key to protecting cloud applications
Infrastructure Information Security
Cloud-native applications have transformed the way businesses operate, enabling faster innovation, greater agility, and enhanced scalability. Yet this evolution brings an equally complex security landscape.

Read more...
Factories, grids, and finance: Critical infrastructure cyber lessons of 2025
Asset Management Information Security Industrial (Industry)
Africa has seen an accelerated, large-scale digitisation of our overall industrial base, and this rapid convergence of IT and OT is happening on a foundation that, in essence, was not designed to be cybersecure.

Read more...
Axis signs CISA Secure by Design pledge
Axis Communications SA News & Events Surveillance Information Security
Axis Communications has signed the United States Cybersecurity & Infrastructure Security Agency’s (CISA) Secure by Design pledge, signalling the company’s commitment to upholding and transparently communicating the cybersecurity posture of its products.

Read more...
Eight African cybersecurity trends for 2026
Information Security
Check Point Software Technologies has released eight critical trends shaping Africa’s digital turning point in 2026, noting that their implementation will require the government, the private sector, and key civic institutions to cooperate.

Read more...
The year of the agent
Information Security AI & Data Analytics
The dominant attack patterns in Q4 2025 included system-prompt extraction attempts, subtle content-safety bypasses, and exploratory probing. Indirect attacks required fewer attempts than direct injections, making untrusted external sources a primary risk vector heading into 2026.

Read more...
AI cybersecurity predictions for 2026
AI & Data Analytics Information Security
The rapid development of AI is reshaping the cybersecurity landscape in 2026, for both individual users and businesses. Large language models (LLMs) are influencing defensive capabilities while simultaneously expanding opportunities for threat actors.

Read more...
SMARTpod Talks to Check Point Technologies about the African Perspectives on Cybersecurity report
SMART Security Solutions News & Events Information Security Videos
SMART Security Solutions spoke with Check Point's Hendrik de Bruin about the report, the risks African organisations face, and some mitigation measures.

Read more...
Securing the smart fleet
Information Security Transport (Industry) Logistics (Industry) IoT & Automation
Contributing around 10 to 12% of South Africa’s GDP, the transport and logistics sector supports almost every part of the country’s economic activity. The stakes for keeping these systems secure are higher than ever before.

Read more...
Who are you?
Access Control & Identity Management Information Security
Who are you? This question may seem strange, but it can only be answered accurately by implementing an Identity and Access Management (IAM) system, a crucial component of any company’s security strategy.

Read more...
Check Point launches African Perspectives on Cybersecurity report
News & Events Information Security
Check Point Software Technologies released its African Perspectives on Cybersecurity Report 2025, revealing a sharp rise in attacks across the continent and a major shift in attacker tactics driven by artificial intelligence

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.