Thursday, October 20, 2005

Top Security Mistakes to avoid Ver 2


The first time we posted this opinion piece it was one of the most popular stories read last month on this blog. Since it was posted we have collated the findings of our global CxO Security Assessment survey and are now in a position to improve and revise the list of Top customer security mistakes, this time separated into "Soft mistakes"(less obvious/subtle mistakes) and "Hard Mistakes" (more obvious and conscious mistakes.)

The story behind this list is as follows : as I consult and do security assessments with many customers, I am fairly accustomed to telling them what to do. However, every now and again a shrewd IT manager or CSO/CISO will ask me "What mustn't I do?". Initially I couldn't provide an answer, but after a while I understood the crazy logic. Faced with the challenge of 100 things that need doing in a security program, perhaps it does make sense to look at the things NOT to do first - maybe the list is shorter and it will help you priorities things!

Soft Mistakes

  1. Not having an information security strategy
  2. Failure to get executive support for your security program
  3. failure to track key security metrics
  4. Thinking that security is only a technology or IT Dept. problem
  5. Underestimating the costs of "catching up" when the need arises
  6. Thinking that you can't be held liable for lax security
  7. Equating compliance with security
  8. Failure to realize value of your information and organizational reputation
  9. Failure to understand relationship of IT to the business process
  10. Failure to consider security in outsourcing and collaboration relationships

Hard Mistakes

  1. Authorizing short term "knee jerk" fixes
  2. Assigning untrained people in unorganised fashion to maintain security
  3. Failure to recognize importance of security awareness programs
  4. Failure to realize that traditional perimeter security is dead
  5. Failure to protect laptops, PDA's and corporate home-use computers
  6. Failure to institute effective change management
  7. Failure to implement a defense-in-depth strategy
  8. Failure to learn from others' mistakes!
  9. Failure to implement a vulnerability management strategy
  10. Failure to realize that viruses, worms, spyware and Spam are a business continuity issue and not just a nuisance.

RELATED TOPICS : This article was subsequently published in a few European countries.

CATEGORIES: 1opinion piece, 1trends, 1best practices,1survey, 1users

Rate this post: (Provided by NewsGator)


Post a Comment

Links to this post:

Create a Link

<< Home