Sunday | 12 October, 2008
Computerworld
Firms need structured security policies, says Gartner
Plus 'obvious consequences for non-compliance by staff'
Leo King (Computerworld UK) 19/09/2007 08:53:08

Related Features
  • +

    Building High-Performance IT Teams 10/12/2007 13:11:09

    Teams play major roles in almost every area of IT, but it’s a challenge to build high-performance teams that can stay together and generate top-quality work
    Teams are pervasive in the world of it, and they come in many different flavours. Short-lived, single-purpose teams are often assembled to get one task completed. Project-oriented teams construct multifaceted solutions addressing complex but finite problems, and product development teams tend to be diverse in composition but stable over time. Within many organizations, a great deal of energy goes into building high-output IT teams that are sustainable in the long term
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    9 Paths to Higher Performance 10/12/2007 14:09:23

    When an organization brings together talented people in a creative, collaborative environment it fosters a culture of high performance, which in turn leads to superior business results
    Like high-achieving individuals, some organizations seem to have the Midas touch. Virtually every initiative they touch earns them gold and even those that fail never seem to cost them much of anything at all
  • +

    Doing Your Sums on . . . Build, Buy or Rent 05/11/2007 13:32:30

    You’re trying to build a world-class IT team, but everyone’s going after the same talent pool. What mix works best? Should you grow your own, draft your players or barter your way to the line-up you want to field?
    CIOs should never forget that while new technologies have a maturity cycle, the maturity cycle for human beings in IT is even longer
  • +

    How to Get Real About Strategic Planning 04/02/2008 12:50:59

    Everyone agrees that having a strategic plan for IT is a good thing but most CIOs approach the process with fear and loathing. In fact, the majority of CIOs (and the enterprises they work for) are faking it when it comes to strategic planning. Isn't it time we all got real?
    Oh, it must be nice to be the CIO of a FedEx or a GE or a Credit Suisse. Places where IT and the business are so tightly aligned you can barely tell the two apart. Where corporate leaders understand that IT is a strategic asset and support it as such
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

It is essential for any business to have a structured security policy with clear language to address all levels of employees, a Gartner analyst has warned.

Speaking at Gartner's IT Security Summit in London, Les Stevens said it was crucial for businesses to start recognizing the key factors influencing the success or failure of policy management.

Many businesses failed to learn from actions that hurt the development of successful policies, he said. These included a low focus on business requirements, risk and implementation, alongside too much focus on pleasing managers and on fitting in with audit requirements -- all to the detriment of building policies specific to the business.

Another problem identified by Stevens was the lack of management support and weak communication culture in some organizations.

"What you need is clear and concise content, a clear definition of roles and responsibilities, a defined purpose, and obvious consequences for noncompliance by staff. It also needs to be in the language of the audience," he said.

"The implementation must fit within the culture of the organization, and be regularly reviewed and maintained. There have to be audits of how well the company is sticking to these policies."

It was essential to have both a hierarchy of policies and of responsibilities in implementing them, said Stevens. To implement policies, he said a top-down charter was needed, together with generic policies and more specific plans for departments, alongside non-enforced standard procedures and guidelines.

The chief information security officer and the chief executive should have responsibility for security policy development, Stevens said, while the information security committee should be in charge of the approval and implementation of that policy.

More about Gartner
Market Place

Computerworld Member Login


 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Understanding Email Marketing: A Guide for SMBs

Email marketing is often viewed as a marketers silver bullet. If used effectively, email campaigns will provide strong results for a limited spend each and every time. Download this white paper to discover how email marketing can work for you and your business.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links