12 keys for locking up tight
In a perfect world, a bit of common sense and a dash of due diligence would protect us from hackers, saboteurs and the common cold. Well, the world isn't perfect, and we know we can never be completely secure. There is a measure of safety to be gained by following a formula of threat education, security breach prevention and risk mitigation. "There's no single answer," says Bruce Schneier, CTO of security consultancy Counterpane Internet Security in San Jose, Calif., and the author of Secrets & Lies: Digital Security in a Networked World (Wiley, John & Sons, 2000). "I can't say, 'Do these seven steps and you'll be magically secure.'" Although every organization's security infrastructure must be unique to be effective, Schneier and other experts point to the following essential ingredients. Pay close attention to these basic security issues.
1. Establish Accountability Companies have traditionally relegated security to IS, viewing it merely as an administrative function and expense. However, security can no longer be a closeted IT function, says Michael Assante, cofounder and chief intelligence officer of LogiKeep, a security consultancy based in Dublin, Ohio. "It's got to be a boardroom issue and not a backroom issue. It needs to become part of a business decision-making process, looking at system survival and business continuation issues. Accountability should fall on the shoulders of the business decision makers."
As the liaisons between operations and management personnel, CIOs are uniquely positioned to champion IT security issues in their organizations, according to John S. Tritak, director of the Critical Infrastructure Assurance Office with the U.S. government. CIOs and other senior IT executives need to cultivate and maintain close relationships with senior operations, telecommunications, physical security, human resources and other executives in their organizations to develop and implement a comprehensive IT security plan.
CIOs must have the authority and the autonomy to immediately address security issues or react to breaches quickly, says the executive vice president of IT at a Fortune 500 financial services corporation. "You can't create a ton of bureaucracy that makes it impossible for you to act or quickly react," he says. "It's called accountability."
Some companies are hiring vice presidents of security and chief information security officers to put policy, processes and methodology in place. Some are hiring chief privacy officers to oversee privacy issues. However, these positions must be more than window dressing, security experts say.
2. Promote Awareness A lack of awareness of the potential threats from the CEO down is a major barrier to implementing security. "It's difficult to move a security initiative forward because most people internally see it as a bureaucratic administrative kind of thing," says the CIO of a Fortune 1000 manufacturing company. "It doesn't matter how many times you wave policies in front of them; it has a half-life of about five minutes in their minds."
CIOs need to raise internal awareness of security among senior management and all employees through ongoing security awareness programs and wide distribution of policies and procedures. "It's incumbent upon the
Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.
Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.
Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.







