SmallBizResource Blog -- Security
10 Security Best Practices To Make Your Business Safer In A Recession
With the recession, it's tempting to cut corners anywhere you can, but security isn't the place to do it -- you may save some short term cash, but recovering from a breach will cost you much more. Fortunately, keeping your business secure isn't just about spending more.
David Kelleher, communications and research analyst for GFI Software, cites a Forrester Research study that found SMBs spent almost 10% less on security in 2008 than in 2007, yet asserts that despite the recession, security spending will increase. According to Kelleher, small and midsize businesses struggle to balance spending with security and the human error that ranks foremost as a vulnerability for SMBs. To help business owners and IT managers manage business security, Kelleher recommends the following best practices:
- Determine Vulnerability -- Conduct an extensive audit of all security measures in place -- all hardware, software and other devices - and the privileges and file permissions given to all employees in the organization. Actively test the security of the storage environment and check the logs of the network and storage- security controls such as firewalls, IDSs and access logs to see if anything was discovered and highlighted as a possible security event. Event logs are an important, but often neglected, source of security information.
- Monitor Activity -- Monitor user's activity 24 x 7 x 365. For a single administrator, monitoring event logs and carrying out regular audits is a massive undertaking. However, it might be realistic to monitor the logs within the storage environment rather than the entire network. Logs have proven to be a source of great value if a security breach occurs and an investigation ensues. Logs analysis transcends all of this as it is not only a post event type of tool but it also allows you to better understand the way your resources are being used and allows for improved management of it.
- Control Access -- Access to data should be given only to those who need it, even if that person happens to be your cousin or the boss's son.
- Safeguard Information -- Safeguard all business information. The use of uncontrolled portable storage devices, such as flash drives and DVDs, puts considerable volumes of data at risk. These devices are easy to lose and they can be stolen quite easily if left lying around. In many cases, the data that is on portable storage devices is often not protected using encryption.
- "Need-To-Know And Need-To-Use" -- Enact technological barriers that permit device use according to a clear and defined policy. Recent studies show that data leakage by employees increases when people lose their job. Portable devices such as USB stick or PDAs can hold large volumes of data. Monitoring and controlling their use on the network is key to reducing the risk of data leakage or malicious activity by disgruntled employees. Use of devices should be restricted to those who really need to be mobile.
- Data Handling Policies -- Implement stringent security policies with regard to how data is accessed, handled and transferred. Technology alone will not protect a company's data. Strong and enforceable security policies as well as employee and management's awareness of security issues will go a long way towards improving the level of storage security within an organization.
- Simple Employee Communication -- Explain the meaning of each policy in clear and simple language how each one is implemented throughout the organization.
- Employee Education -- Employees need to be reminded that they should not leave their passwords written on a sticky note on their monitor. They need to understand that sharing passwords is equivalent to sharing the key to their home. They need to be told not to divulge any information to third-parties without authenticating the request. They need to have a basic understanding of security and the most common threats, e.g., e-mail phishing and social engineering. Additionally, they should be reminded that their actions are being monitored and that they are accountable to the company.
- Backup Everything -- Backup all communications and data to, from and within the business. Check your backups regularly to ensure that if the company's network is down, you can get everything online in a short time-frame. You don't want to be in a position where your backups are corrupt.
- People Management -- Storage security is more than protecting the data using technology or placing it under lock and key, it is also an exercise in people management. The people using and creating the data are the greatest threat and weakest security link.
|
|
REGISTER NOW! |
Don't Miss: Keith Ferrell's Security Blog
This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.
Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.
Important Note: This comment area is NOT intended for commercial messages or solicitations of business.
| Latest InformationWeek SMB Features for Small Biz |
| Exclusive Research for Small Biz |
Explore the Small Business Resource Blog
Topics
- AMD Sponsored Blog Post
- Business Know-How
- Customer Service
- Economy
- Freelancing
- Government
- Green
- Hardware
- Imaging How-To
- Internet
- Marketing
- Mobility
- Networking & Communications
- Productivity
- Research
- Retail
- Security
- Server How-To
- SmallBizResource
- Software
- Startups
- Storage
- Women in Business
Blog Roll
- All Things Digital
- BizWomen
- bMighty.com
- Business Know-How
- Cool Business Ideas
- Digital Download
- Duct Tape Marketing
- Entrepreneur.com Daily Dose
- The Entrepreneurial Mind
- Escape from Cubicle Nation
- Freelance Switch
- Guy Kawasaki
- InformationWeek
- New York Enterprise Report Blog
- Practically Speaking, The New York Times
- Seth Godin
- Shifting Careers, The New York Times
- Smallbiztechnology.com
- Small Biz Trends
- Tech Crunch
- USA Today Technology Live
Blog Archives
- February 2010
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
| A QUICK UPDATE FOR OUR VISITORS | |
|



