Manager’s guide: Tailor-made security policy

August 2014 Information Security

With the never ending number of security threats to business information it is imperative that managers take the initiative to establish working and evolving security policies that protect the business and its assets. As the popular saying goes, “prevention is better than cure” and nothing could be more pertinent to the importance of having a security policy in a business. But where to start?

Gregory Anderson, country manager at Trend Micro South Africa.
Gregory Anderson, country manager at Trend Micro South Africa.

Establish security threats to your business

In order to face up to threats you need to be savvy about them. With today’s identity theft, spam and spyware – software that secretly monitors a user’s activity with the intention of information theft – you may be surprised by how fundamental some of the biggest threats are. IT threats are constantly evolving, which is why it’s important that your security policy and plans do the same. Keep your system flexible enough to meet not only present but future problems as well.

Bear in mind the legislation involved in your IT responsibilities, privacy and electronic communication responsibilities and your treatment of employees as well as the regulations from the European Commission. Also remember that every business has different information security threats, some unique and some universal, the manager’s job is to account for all existing and possible threats to security and tailor a security policy that will counteract them.

Establishing a security policy

All-encompassing IT security is built on the foundation laid by a company security policy. A good place to start when creating a security policy for your business is with the risk analysis of what threats are posed to your business. A layered approach is necessary to cover all bases starting with a mission statement from a manager and moving into physical devices, roles and responsibilities of staff, including references to acceptable use and how security breaches will be dealt with. This is also a great place to host your business continuity and disaster recovery plans.

Next, you need to sort out what to include in the security policy. A clear explanation of the purpose of the policy, its ultimate goals and strategic importance of information security to the business should be the first thing on the agenda.

Make a list of the training available to employees to help them better understand information and security risks. It is imperative to give the policy authority by including a statement of support from senior management demonstrating a commitment to information security. Remember that every business will have different security needs so the most important things to include in the security policy will differ from business to business.

Protecting your IT assets

IT asset protection starts with providing your staff with clearly communicated guidelines on acceptable use, confidentiality and standards for security measures. An explanation of what is and isn’t allowed on company time and company computers and outlines the repercussions for disregarding the policy ensures that staff do not expose the company to malware, share confidential information over the Internet or take sensitive information off-site on laptops or USB drives.

Staff will understand the importance of an acceptable use policy as long as it strikes a balance between pragmatism and control and the company is clear about the risks it is trying to avoid. In order to weave acceptable policy usage into the culture of the company tie them into employee contracts and disciplinary procedures.

A functioning security policy

Think of your company security policy as a never ending work in progress that you definitely shouldn’t leave collecting dust. For a security policy to be meaningful it needs to be a living, breathing document that management and staff access and refer to. The fundamental elements of a security policy are management’s visible commitment to it, employee awareness and education on the security policy as well as ensuring that the policy remains relevant and up to date.

After you have put together the company security policy you need to determine how you will administer security which will come down to a mixture of people, policies, processes and technology all of which play a critical part in ensuring overall security. If businesses are small it is unnecessary to take on additional staff to administer IT security systems, you can rather give the responsibility to existing managers. However, if an external consultant is called upon to set up the security policy, ensure that they report back to management at every step as you shouldn’t leave it to an outsider to keep you safe.

As a manager it is your responsibility to ensure that your staff and colleagues understand the importance of the security policy. With the number of IT security threats increasing and strengthening constantly it is important to be aware that your business is as viable a target as anyone else’s. Breaches to security are no longer a question of ‘if’ but ‘when’ and if you have tailored a security policy to your business you and your staff will be prepared to handle inevitable breaches of security.

For more information, visit www.trendmicro.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
African industries may overestimate cyber defences
Information Security
] A significant perception gap exists in security awareness training: 68% of leaders believe training is tailored to roles, yet only a third of employees feel adequately trained. Many organisations only conduct annual or biannual generic training that may not effectively change behaviour.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.