- The 10 dumbest mistakes network managers make
- Six Windows 7 features admins will actually care about
- Why the iPhone can't be "killed"
- Nortel enterprise chief wants to bring back Bay
- More porn sneaks onto the iPhone
A child with a chocolate-smeared shirt says, "I didn't do it." The phone rings, and Mom assures you, "There's nothing to worry about." A systems administrator carrying a box of tapes says, "We'll have everything back up in a few minutes." Sometimes the first words you hear -- despite their distance from the truth -- tell you everything you need to know.
That's so with information security as well. Some words sound reassuring at first glance, but I've found they often point to problems safeguarding internal information assets and technical resources, or with the people and processes that protect them. Here are a few of the telltale phrases signaling that security trouble could be boiling over.
1. "We have a culture of security."
No, you don't.
I hear this most often from enterprises that started as a five-person mom-and-pop shop, went corporate as they grew, then blinked and found themselves operating with a thousand people and no governance or policies. Three dollars and their "culture of security" will get you a fancy cup of coffee in a quiet cafe, where you can contemplate how much work there is to do.
The simple fact is that without supporting directives or a mechanism for feedback, security is defined differently by each person and verified by no one. There is no metric for compliance with a "culture," and a "culture of security" is overridden by a culture of "get the job done" every time.
If there are rules, write them down. If technology is put in place to implement or monitor the rules, write that down too. If people break the rules, follow up. If the rules prevent legitimate business from getting done, change them. It's that simple.
2. "IT security is information security here."
Information security is not the same thing as security in information technology. If the term "information security" is used interchangeably with "IT security," it invariably means that no one has made fundamental nontechnical security decisions and that affected departments -- IT, human resources, legal, audit and perhaps others in your organization -- are guessing what the others mean.
Get together with those who have influence in the departments above, and decide whether information (not paper documents or equipment) is an asset of the company, just like computers and paper clips. Decide whether the company authorizes people for jobs, physical access and information as individuals. Make these policy decisions as a group, and have them signed by those with authority. Then perhaps there will be more time in the day for deciding how to manage security instead of guessing what.
Comments (2)
I truly enjoyed your contentBy Anonymous on August 20, 2007, 12:18 pmI truly enjoyed your content and the delivery. Thanks - there is a lot of truth here, and some well-phrased ideas.
Reply | Read entire comment
RE: 10 claims that scare security prosBy Raymond Davey on August 16, 2007, 3:48 pmHow true! (and funny!) Thanks for lightening this topic up a bit and adding some very practical advice.
Reply | Read entire comment
View all comments