Information Security For Business

What is the Best Approach to Provide Security?

We protect our homes and cars in a systematic manner, perhaps with door and window locks, intruder alarm systems and car immobilisers. We think about what the risks are and introduce relevant countermeasures.

Protecting your company information requires a similar approach.

The most effective way of providing information security is to use a structured approach based upon your specific security requirements. This will ensure that you concentrate on the important areas.

A Code of Practice for Information Security Management was published in 1995 as a British Standard, BS 7799. This provides a comprehensive set of security controls comprising the best information security practices in current use. It s objectives are to provide organisations with a common basis for providing information security and to enable information to be shared between organisations.

BS 7799 contains many controls and identifies ten that are considered ‘key’ controls. You should consider implementing these ten controls as a baseline across your organisation. In some important specific business areas you may wish to implement additional controls and security measures. The ten key controls are discussed in more detail in the section How do I provide security solutions?

BS 7799 – The Ten Key Controls

  1. information security policy document
  2. allocation of information security responsibilities
  3. information security education and training
  4. reporting of security incidents
  5. virus controls
  6. business continuity planning process
  7. control of proprietary software copying
  8. safeguarding of organisational records
  9. data protection
  10. compliance with the security policy

Read the next part of the Information Security for Business guide – What Roles and Responsibilities Should I Consider?

1 2 3 4 5 6 7 8 9

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>