Disaster-Resource.com


How to Get Everyone on Board for Security

Information security professionals often face problems when developing, implementing and enforcing security policies, and even when their companies accept that they need policies, many projects are still given a low priority. So how can IT pros keep from feeling like an army of one?

In an article on the Search Security.com website, information security expert Harris Weisman says “many information security professionals, although recognizing security polices were important, were willing to accept that policies were a low priority for the organization.

But with changes in the legislative climate and rules like SOX, GLBA and HIPAA, many companies are bringing security to the front burner. That’s why Weisman says IT security pros “must therefore spur the organization into action.”

In his article, he examines several ways IT pros can enlist help from inside and outside the organization. Among his suggestions are the usual getting executive management involved, getting the board of directors involved and getting auditors involved. He also suggests using existing policy resources from security organizations like SANS, talking to their counterparts in other companies and training all employees on security policies.

To read the full article, click here: http://searchsecurity.techtarget.com/tip/1,289483,sid14_gci1194097,