professional documents
home
Upload
docsters
Upload
Acrobat PDF

Security Template center doc

Objective Put security controls into the hands of the systems specialists. System Specialists, and Project Manangers, know their technology needs and requirements the best. Hand the choices of individual security controls to the business units that owned the data in question. Someone to decipher the business needs into technical solutions and vice versa. Solution Company Information Security Advisers, coordinating security requirements between IT and business units. Bridging the divide between technology requirements and business requirements. Bridging this gap takes a certain amount of credibility, which comes from the backing of the most senior IT manager, as well as the most senior company management. Once this backing is obtained, approach this challenge on two fronts -raising IT awareness in the user community and raising business awareness in their IT support departments. Process -Tool 1. Develop a 10-point template from which business units can make informed decisions about their security needs. At the onset of any new project, the security advisers meet with the business units to discuss their needs and go over the template. That means asking the right questions, like the following: What are your strategic directions? What do you deal with? What information is confidential? What level of protection does that information require? 2. Once the business unit fills out a project security template, a business partner document is generated. Then the security advisers work with the technologists to address the security areas identified by the business units. 3. After that, they have to find a way to bring the business mentality of budgets, policies, operational integration and more into IT development teams. 4. Ask the technology units similar questions, so they can see IT security as a strategic business enabler and overcome their misconceptions that security gets in the way of efficiency. 5. The final decision still needs to be made by the data owners. Once the technical specialists turn around a list of suggested solutions to meet the business units' risk requirements, the advisers return to the business units and discuss levels of risk with the business managers who make the final technical security choices that go into the project. © Copyright 2001. Melissa Guenther, LLC. All rights reserved. mguenther@cox.net Security Template When undertaking a new development project, enable the business unit project managers to set security requirements themselves. A key element is a template that explains key terms: Authentication: Who are you? Authorization: What can you do? Confidentiality and reliability: Privacy and dependability Monitoring and tracking: What did you do? Backup and recovery: Rebuilding the system Physical security: Locking others out Change management: Protecting the production process Legal requirements: What the law expects Training and awareness: What you need to know Contingency planning: What if? Next Steps The final decision still needs to be made by the data owners. So once the technical specialists turn around a list of suggested solutions to meet the business units' risk requirements, the advisers return to the business units and discuss levels of risk with the business managers who make the final technical security choices that go into the project. © Copyright 2001. Melissa Guenther, LLC. All rights reserved. mguenther@cox.net
rate this doc
email this doc
embed this doc
add to folder
digg reddit stumble delicious
flag this doc
131
5
not rated
0
2/2/2008
English
Preview

Select Agents and Toxins Security Plan Template

anonymous 2/2/2008 | 122 | 2 | 0 | business
Preview

Template for professional development planning

anonymous 2/2/2008 | 384 | 55 | 0 | business
Preview

Free Powerpoint Templates - Professional Looking Template

Thycid 2/11/2008 | 223 | 12 | 0 | creative
Preview

templates for customizing

PrivateLabelArticles 8/19/2008 | 204 | 2 | 0 | business
Preview

Employee Expense Report - Free Professional Documents HR Forms and Templates

bamafun 6/30/2008 | 169 | 14 | 0 | business
Preview

Template+for+professional+developme nt+planning

trepid 4/7/2008 | 154 | 6 | 0 | business
Preview

PROFILE TEMPLATE

anonymous 2/2/2008 | 245 | 23 | 0 | business
Preview

CV-Template

anonymous 2/2/2008 | 292 | 20 | 0 | business
Preview

Manuscript template

anonymous 2/2/2008 | 187 | 8 | 0 | business
Preview

Proceedings Template

anonymous 2/2/2008 | 48 | 0 | 0 | business
Preview

Style Template

anonymous 2/2/2008 | 131 | 3 | 0 | business
Preview

Timetable Template

anonymous 2/2/2008 | 241 | 2 | 0 | business
Preview

WORKSHOP TEMPLATE

anonymous 2/2/2008 | 124 | 8 | 0 | business
Preview

AP Professional Development Coordinator

PrivateLabelArticles 8/19/2008 | 29 | 2 | 0 | business
Preview

Election of Professional Corporation Status_ PA Template

LisaB1982 4/2/2008 | 36 | 0 | 0 | legal
 
review this doc