Manager’s guide: Tailor-made security policy

August 2014 Information Security

With the never ending number of security threats to business information it is imperative that managers take the initiative to establish working and evolving security policies that protect the business and its assets. As the popular saying goes, “prevention is better than cure” and nothing could be more pertinent to the importance of having a security policy in a business. But where to start?

Gregory Anderson, country manager at Trend Micro South Africa.
Gregory Anderson, country manager at Trend Micro South Africa.

Establish security threats to your business

In order to face up to threats you need to be savvy about them. With today’s identity theft, spam and spyware – software that secretly monitors a user’s activity with the intention of information theft – you may be surprised by how fundamental some of the biggest threats are. IT threats are constantly evolving, which is why it’s important that your security policy and plans do the same. Keep your system flexible enough to meet not only present but future problems as well.

Bear in mind the legislation involved in your IT responsibilities, privacy and electronic communication responsibilities and your treatment of employees as well as the regulations from the European Commission. Also remember that every business has different information security threats, some unique and some universal, the manager’s job is to account for all existing and possible threats to security and tailor a security policy that will counteract them.

Establishing a security policy

All-encompassing IT security is built on the foundation laid by a company security policy. A good place to start when creating a security policy for your business is with the risk analysis of what threats are posed to your business. A layered approach is necessary to cover all bases starting with a mission statement from a manager and moving into physical devices, roles and responsibilities of staff, including references to acceptable use and how security breaches will be dealt with. This is also a great place to host your business continuity and disaster recovery plans.

Next, you need to sort out what to include in the security policy. A clear explanation of the purpose of the policy, its ultimate goals and strategic importance of information security to the business should be the first thing on the agenda.

Make a list of the training available to employees to help them better understand information and security risks. It is imperative to give the policy authority by including a statement of support from senior management demonstrating a commitment to information security. Remember that every business will have different security needs so the most important things to include in the security policy will differ from business to business.

Protecting your IT assets

IT asset protection starts with providing your staff with clearly communicated guidelines on acceptable use, confidentiality and standards for security measures. An explanation of what is and isn’t allowed on company time and company computers and outlines the repercussions for disregarding the policy ensures that staff do not expose the company to malware, share confidential information over the Internet or take sensitive information off-site on laptops or USB drives.

Staff will understand the importance of an acceptable use policy as long as it strikes a balance between pragmatism and control and the company is clear about the risks it is trying to avoid. In order to weave acceptable policy usage into the culture of the company tie them into employee contracts and disciplinary procedures.

A functioning security policy

Think of your company security policy as a never ending work in progress that you definitely shouldn’t leave collecting dust. For a security policy to be meaningful it needs to be a living, breathing document that management and staff access and refer to. The fundamental elements of a security policy are management’s visible commitment to it, employee awareness and education on the security policy as well as ensuring that the policy remains relevant and up to date.

After you have put together the company security policy you need to determine how you will administer security which will come down to a mixture of people, policies, processes and technology all of which play a critical part in ensuring overall security. If businesses are small it is unnecessary to take on additional staff to administer IT security systems, you can rather give the responsibility to existing managers. However, if an external consultant is called upon to set up the security policy, ensure that they report back to management at every step as you shouldn’t leave it to an outsider to keep you safe.

As a manager it is your responsibility to ensure that your staff and colleagues understand the importance of the security policy. With the number of IT security threats increasing and strengthening constantly it is important to be aware that your business is as viable a target as anyone else’s. Breaches to security are no longer a question of ‘if’ but ‘when’ and if you have tailored a security policy to your business you and your staff will be prepared to handle inevitable breaches of security.

For more information, visit www.trendmicro.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
The deepfake crisis is here and now
Information Security Training & Education
Deepfakes are a growing cybersecurity threat that blur the line between reality and fiction. These AI-generated synthetic media have evolved from technological curiosities to sophisticated weapons of digital deception, costing companies upwards of $600 000 each.

Read more...
What does Agentic AI mean for cybersecurity?
Information Security AI & Data Analytics
AI agents will change how we work by scheduling meetings on our behalf and even managing supply chain items. However, without adequate protection, they become soft targets for criminals.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...
Crypto in SA: between progress and precaution
Information Security
“As cryptocurrency gains momentum and legitimacy, it’s becoming increasingly important for people to pay attention to financial security”, says Richard Frost, head of technology and innovation at Armata Cyber Security.

Read more...
Cyber recovery requires a different approach to disaster recovery
Information Security
Disaster recovery is about getting operations back on track after unexpected disruptions; cyber recovery, however, is about calculated actions by bad actors aiming to disrupt your business, steal sensitive data, or hold your system hostage.

Read more...
MDR users claim 97,5% less
Sophos Information Security
The average cyber insurance claim following a significant cyberattack is just $75 000 for MDR users, compared with $3 million for endpoint-only users, according to a new independent study.

Read more...
The impact of GenAI on cybersecurity
Sophos News & Events Information Security
Sophos survey finds that 89% of IT leaders worry GenAI flaws could negatively impact their organisation’s cybersecurity strategies, with 87% of respondents stating they were concerned about a resulting lack of cybersecurity accountability.

Read more...
Efficient, future-proof estate security and management
Technews Publishing ElementC Solutions Duxbury Networking Fang Fences & Guards Secutel Technologies OneSpace Technologies DeepAlert SMART Security Solutions Editor's Choice Information Security Security Services & Risk Management Residential Estate (Industry) AI & Data Analytics IoT & Automation
In February this year, SMART Security Solutions travelled to Cape Town to experience the unbelievable experience of a city where potholes are fixed, and traffic lights work; and to host the Cape Town SMART Estate Security Conference 2025.

Read more...