How to improve your IT. Part 12 – Security

IT
IT Security

IT Security

A series of posts on how to improve the performance of your IT

The Best practice IT Standard is comprised of:

Five levels of managed security with penetration testing, underpinned by CARTA (a strategic approach to information security that was introduced by Gartner in 2017).

Security levels

  1. IT security. Refers to securing digital data, through computer network security. It is accountable for preventing unauthorized access to organizational assets such as computers, networks, and data and it maintains the integrity and privacy of corporate information and the blocking of hackers.

  2. Information security, on the other hand, refers to the processes and tools designed to protect business information from unauthorised access.

  3. Network security. Used to prevent unauthorized or malicious users from getting into a network, ensures that capacity, reliability, and integrity are not compromised. The Network security risk profile increases as business increase the number of endpoints and migrates services to the public cloud.

  4. Endpoint security. Protects mobile phones, laptops, and desktops. It restricts access to malicious and typically includes malware protection and device management.

  5. Internet security. The protection of information that is sent and received in browsers. Includes network security involving web-based applications. These protections come in the form of firewalls, anti-malware, and anti-spyware, ransomware.

  6. Cloud security. Applications and data held in a cloud-based data centre. The usual security measures do not protect users who are connecting to the internet. Cloud security secures software-as-a-service (SaaS) applications and the public cloud.

CARTA

Within the CARTA approach, decisions and security responses are made based on risk and trust. There are three phases of IT Security where CARTA plays a role:  Run, Plan and Build.  In the Run phase, CARTA lets the organization use analytics to focus only on the biggest threats and automate the majority of the incidents.  In the Build phase, CARTA plays a role in DevSecOps, as teams identify threats and eliminate them from apps they are building and use things like a digital risk rating service to analyse open-source components they may want to use.  In the Plan phase, CARTA invites organizations to use analytics to determine the risks of things such as having employees change passwords frequently versus the productivity impact and decide how much risk to accept. (Source, SUSE).

Performance Assessment

  1. Does your security function cover the five security types?

  2. Is there a security manager?

  3. Does the security manager report to the Infrastructure manager?

  4. Is your security managed in-house, or is it outsourced?

  5. What types of annual penetration testing takes place?

  6. What resolution times for new threats are you receiving from your external suppliers?

  7. What is the number of security violations per month?

  8. Are the security violations trending upward?

  9. What is the number of monthly security violations/hacks by security type?

Sample Tasklist

  1. Carry out a risk analysis of the five security functions.

  2. Review all five levels of security for completeness.

  3. Arrange external penetration testing.

  4. Define and design a systems security architecture.

  5. Determine further works required and scope out.

  6. Break down the scope of works to the task level, ready for loading into the change management project schedule.


You can share this post by using the buttons below

You can follow me on Facebook, Twitter, LinkedIn, Medium and Slideshare

Russell Futcher

Russell Futcher lives in Melbourne Australia as an IT/Business Change Management Consultant. He is a recognised High-Performance Management and Teams specialist, an author, researcher and blogger. His 40-year career to date has been focussed on Change Management where he has gained a hard-earned reputation for someone who takes on complex jobs and gets things done. Frank and direct, highly regarded by peers and customers alike, highly motivational and passionate about fixing problems, improving performance and developing management and team talent.

Russell has held senior management positions across the Insurance, Banking, Health, Transport, Retail, Superannuation, and Technology sectors in some of Australia’s largest corporations. Qualified in Business and Executive Coaching, Management Development and Training and Education, he is also the developer of the ‘Best Practice IT Standards’ and the ‘High-Performance Management and Teams’ management model, author of five management books and three courses.

An experienced electronic and print media presenter who spends much of his spare time doing research into Management and Team behavioural dynamics. His favourite subject he says is - people, stating that “Everyone is fascinating, and I just like everyone".

http://russellfutcher.com
Previous
Previous

How to improve your IT. Part 13 – Projects and Project Management Office

Next
Next

High-Performance Teams - Reasons and Goals?