This page contains a Flash digital edition of a book.
12


The Effectiveness of Information when


Information security has matured over recent years; once sidelined and overlooked, we now find ourselves presenting to senior management and influencing corporate strategy.


With this higher profile comes responsibility and an increasing need to deliver a demonstrably effective solution that offers proven value for money. We understand, however, that risk can be mitigated but it can never be eradicated completely , as such, it is possible to make a massive investment in security technology, process and resource and still suffer an incident. Few roles suffer the same challenge, where a well-conceived, well-funded and a secure solution may become vulnerable through no action, or inaction, from your staff - truly the modern IT Security Manager has a difficult balancing act to manage. To understand the effectiveness of the security policy in place at your organization, it is important to appreciate both the global threats and the risks that apply to your firm and sector. Discussions with peers, industry research and viewing the controls from the user’s perspective all help in this regard. Understanding and quantifying the risks arising from these threats provides a first baseline to measure effectiveness. Once the threats are understood, the next key step


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36  |  Page 37  |  Page 38  |  Page 39  |  Page 40  |  Page 41  |  Page 42  |  Page 43