SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Security admins make risk management pitch

Security admins make risk management pitch

By:  Rafael Ruffolo  On: 07 Oct 2008 For: ComputerWorld Canada Creator

Representatives from CIBC, Unisys and elsewhere discuss their approach to selling business leaders on the right products and strategy for protecting enterprise information. Coverage from SecTor 2008

And in addition to keeping business leaders in the loop, every security decision should also be weighed against its impact on end-users. David Millier, CEO at SentryMetrics, said as more companies restrict Internet access to their users, many security administrators are fielding calls from unhappy users – many of which need to use specific sites throughout the course of their working day.

“You need to put measures in place to find out if there’s an effective way to enforce the policies you plan to enact, as well as, a way to monitor whether the policy is actually an effective one,” he said. Companies are better off with no policy, as opposed to a false sense of security, Millier added.

Dale Tasker, a former IT security manager with the Government of Ontario, said that along with risk assessment, making sure you’re security measures don’t overtly conflict with your end-users’ ability to function is crucial. Penetration testing before a major application or security project goes live, he said, is a highly valuable best practice.










Sign up for our Newsletters












Print |  Views: 3203   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Rafael Ruffolo Rafael Ruffolo was a senior writer for ComputerWorld Canada from 2006 to 2011. He was the winner of a Kenneth R. Wilson award for business journalism in 2009.

Related Content

ID management offers more than just security
ID management offers more than just security Today’s business is a world of mobile work forces, networks and scattered places where information about employees is stored. Wouldn’t it be great to have technology that makes it easier to manage the flow of corporate information, improve the quality of data gathered by a business, and have a tighter rein on what users can do when it comes to computing?
Enterprise search plans focus on security first
Enterprise search plans focus on security firstWhile the benefits to companies using enterprise search technology, such as Google’s OneBox for Enterprise, are numerous, there’s sometimes hesitation in adopting such organizational methods due to concerns over network security. So what are search companies doing to help make a network manager’s life a bit easier when it comes to search and security?
EMC to acquire RSA Security
EMC to acquire RSA Security In a deal that marries one of the IT industry's biggest data storage vendors and one of its best-known security companies, EMC Corp. unveiled plans to acquire RSA Security Inc. Under the deal, Hopkinton, Mass.-based EMC will pay US$28 a share, or almost $2.1 billion, for Bedford, Mass.-based RSA, according to the companies.
Dan Swanson's Security Resources: #7
have you implemented a security education and awareness program to help educate management and staff on their security responsibilities? have you organized a process to communicate good practice information to your workforce, particularly to the key it specialists that are implementing new it solutions? have you reached out lately to your dr and bcp professionals regarding recovery processes and
blog comments powered by Disqus