|
Organizations
should have an Information Security Program in place to continually
protect against incursion from without and within.
Computers
and digital controls are at the heart of todayís organizations.
As such, the interruption of business systems can disrupt and even
cripple normal business activities. In addition, when systems are
breeched, they expose business operations and information to the
world, the organization to claims liability, and a degradation of
the organizations public image. Incidents can come from thieves,
competitors, disgruntled employees, and hackers from around the
world.
Below is a short list of those who may attempt
to cause an organization mischief or harm:
 |
Competitors
or their agents seeking information about proprietary processes,
financial information, client lists, etc. |
 |
Disgruntled
employees looking to do harm or steal from the organization |
 |
Hackers
looking for the challenge of breaking through the organization's
security systems and gaining a dark badge of honor |
 |
Organized
hacking groups very often associated with foreign organized
crime groups |
 |
Blackmailers
who will find holes in an organization’s security and
then threaten to go public with the information if not paid
a fee |
| Back
to Top ^ |
Every organization should have a comprehensive Information
Security Program tailored to meet the specific requirements of the
organization. They are normally developed in conjunction with the
organization’s IT department and while each is unique, they
can contain, but are not limited to, the following elements:
 |
A thorough
analysis of existing and potential system vulnerabilities from
without and from within |
 |
An investigation
of potential technologies that will offer the proper level of
protection for existing systems and processes |
 |
Once the
new technology is in place, a thorough aggressive testing is
done of the system with the latest incursion technology to ensure
the security of the system |
 |
Develop
and implement an active program to identify and track attempted
incursions with a real-time response mechanism in place for
software, firmware, and hardware |
 |
Develop
and implement an ongoing program to continually monitor and
test the security of the system |
| Back
to Top ^ |
Information System Security is in a continual state
of change and in most cases requires the attention of an outside
organization. For most organizations it is impossible for IT departments
to devote the time and effort it takes to stay on the cutting edge
of its technology and processes.
If you would like information
on developing an Information Security Program, or would like to
discuss a security audit, please contact Cecilia Mendoza
who will put you in touch with one of our senior security consultants.
You can contact
Cecilia Mendoza, Sales Support at +1 602 354 2790
or by email at cmendoza@forensicsconsulting.com.
|