web analytics
364 NEWS
No Result
View All Result
Thursday, May 19, 2022
  • Login
  • Home
  • World
  • Economy
  • Business
  • Markets
  • Tech
  • Real Estate
Subscribe
364 NEWS
  • Home
  • World
  • Economy
  • Business
  • Markets
  • Tech
  • Real Estate
No Result
View All Result
364 NEWS
No Result
View All Result
Home Tech

Security Think Tank: Good documentation could save your bacon

by admin
December 9, 2021
in Tech
0
Security Think Tank: Good documentation could save your bacon
152
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter

Security learning is a career-long process, so as 2021 draws to a close, participants in the Computer Weekly Security Think Tank sum up the most important cyber lessons they’ve taken away from the past 12 months

Petra Wenham

By

  • Petra Wenham

Published: 09 Dec 2021

The year is moving towards its close, Black Friday sales have come and gone and some 50% of those sales were done online, in part due to the ongoing trend to online sales and partly due to the Covid-19 pandemic accelerating that trend.

But, be they big retailers or SMEs moving into the online retail space, how secure are those websites? And how knowledgeable in infosec are the IT companies providing these online infrastructure services?

Security incidents have continued apace during 2021, highlighting the inadequacies of many organisations’ defences. And what weak points these security breaches have shown up! So what lessons have, or should we have, learnt?

For me, two issues stand out. One is that companies or organisations are not fully or properly addressing the basics of infosec. Second is that risk assessments of the IT environment and the data that it contains and/or processes is not being carried out in a full and appropriate manner, or perhaps not carried out at all.

Both of these issues, the basics and risk assessment, boil down to documentation and adequate resources. Resources includes appropriately skilled people and supporting tool sets. Documentation should be comprehensive and kept up to date with regular audits to ensure compliance. It sounds onerous, perhaps in the beginning, but over time, good documentation together with adequate resources will pay back in spades. 

What do I mean by documentation? To me, it includes but is not limited to policies, procedures, standards, work guides and methodologies, including threat and risk assessments, network diagrams, audit files, inventories of hardware, software, licences, the data being held or stored including backup and archive data, process flow charts (essential for virtualised and cloud environments), business continuity and disaster recovery plans, security incidence response plans and emergency response plans and contact lists.

Don’t forget that elements of the IT documentation will necessarily need to dovetail in with other company divisions or external services, including:

  • Business groups identifying who owns which piece or set of data together with statements of who or what needs access to the data in question, its value and what can a process or designated person or group of people do with the data they are accessing. Note that it is not the job of IT to decide what level of security should be applied to any piece or group of data – that is a business function. IT’s job is to interpret the requirements and implement them.
  • Human resources covering staff vetting and hiring procedures, etc.
  • Compliance, legal and regulatory.
  • Building services covering building access security, utilities, air handling, uninterrupted and or emergency power supplies, and so forth.
  • External agencies, including: external service suppliers, eg cloud-based services; manufacturers/suppliers (licensing, updates and patching); internet providers; security consultancies (for information on current threats and vulnerabilities, secondary infosec support, IT health checks and penetration testing); clients where appropriate: government agencies.

In summary, you need accurate, well-maintained documentation to enable the comprehensive management, securitisation and ongoing support of secure IT infrastructure.

I should add a disclaimer: you are never going to be 100% secure, but with good documentation supported by tested backup mechanisms, together a security incident response plan, a company shouldn’t be dead in the water for long should a security breach occur.





Read more on IT risk management


  • Former Ubiquiti engineer arrested for inside threat attack

    By: Arielle Waldman


  • Memento ransomware gang quick to retool for ‘optimum’ outcome

    By: Alex Scroxton


  • ConnectWise platform aims to unify MSP software portfolio

    By: John Moore


  • API security strategies must evolve to include API protection

    By: Sharon Shea

Read More

Tags: SecurityThink
  • Trending
  • Comments
  • Latest
Does omicron cause unusual symptoms?

Does omicron cause unusual symptoms?

December 13, 2021
One person dead following incident at SilverStar Mountain Resort

One person dead following incident at SilverStar Mountain Resort

December 20, 2021
Edmonton Police helping families in need through Holiday Heroes campaign

Edmonton Police helping families in need through Holiday Heroes campaign

December 20, 2021
Amazon staff had to use bathrooms as tornado shelters

Amazon staff had to use bathrooms as tornado shelters

December 13, 2021
Hashtag Trending Dec. 8 – Massive numbers of YouTube copyright strikes; Microsoft seizes hacker’s servers; Outage at AWS

Hashtag Trending Dec. 8 – Massive numbers of YouTube copyright strikes; Microsoft seizes hacker’s servers; Outage at AWS

0
With Stimulus Benefits Ending, What Should Small Business Owners be Aware of?

With Stimulus Benefits Ending, What Should Small Business Owners be Aware of?

0
7 Ways to Be a Truly Customer-Focused Business

7 Ways to Be a Truly Customer-Focused Business

0
Assumptions Can Hold Your Company’s Success Hostage. Here’s How to Fight Them

Assumptions Can Hold Your Company’s Success Hostage. Here’s How to Fight Them

0
Canada Goose forecasts annual profit above estimates on strong luxury goods demand

Canada Goose forecasts annual profit above estimates on strong luxury goods demand

May 19, 2022
Poland’s PGNiG seeks arbitration over Gazprom gas overpayments

Poland’s PGNiG seeks arbitration over Gazprom gas overpayments

May 19, 2022
Stock Rout, Retail Earnings, Sovereign Default

Stock Rout, Retail Earnings, Sovereign Default

May 19, 2022
Sri Lanka Falls Into Default, Sending Warning Across Emerging World

Sri Lanka Falls Into Default, Sending Warning Across Emerging World

May 19, 2022
  • Home
  • Advertisement
  • Contact Us
  • Privacy & Policy
  • Other Links

© 2021 364News - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Advertisement
  • Contact Us
  • Homepages
    • News 364
  • World
  • Economy
  • Business
  • Opinion
  • Markets
  • Tech
  • Real Estate

© 2021 364News - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In