Best security practices don't exist. If they did, the company implementing them would be spending too much money trying to secure its information, and worse, more than likely stopping the business from operating. The best practice for any organization is to evaluate its risk, comply with applicable standards at the minimum level required, and implement just enough control to achieve that state.
There are organizations, such as certain three-letter government agencies, or R&D aspects of companies with high-value intellectual property, transactional or money transfer systems, that require best and state-of-the-art security. For most of the IT world, however, successful IT professionals balance the cost and complexity surrounding security controls, and IT costs in general, to obtain an appropriate and acceptable level of risk.
In the US, the Food and Drug Administration's Web page on information security states that GxP is the current standard for various regulatory compliance areas for pharmaceutical companies. GxP represents Good Practices, not best practices. That is, Good Manufacturing Practice or Good Clinical Practice. This is a bit odd: good enough was the plan of the day for manufacturing life-saving drugs.
Looking further, building codes define "minimal acceptable standards" that homes, lots and structures have to meet. Similarly, in the legal community, there is the standard of the reasonably prudent person. Doctors and other professionals are typically only held to a standard of reasonable or ordinary care, not excellent or the best possible care.
So IT and business professionals should not be asking for best practices, they should determine appropriate and reasonable controls to protect information and maintain compliance with federal regulations. Interestingly, even the regulatory guidelines allow flexibility in approach to controls, as long as the information is adequately protected and based on the use of a documented risk assessment to determine this reasonableness and appropriateness.
To determine if you're spending the appropriate amount on security controls, perform risk assessments for every significant technology decision. Documenting the outcome and how you arrived at your decision helps your organization meet regulatory and legal requirements, and earns you the respect and admiration of the business units and bean counters.
Take, for example, a network architecture migration. Engineers presented a fully redundant, resilient design for a branch office. The design specifications were based on what the engineers termed "best practice" and on input from the remote workers who said they had to be on the network, or their work would grind to a halt.
A risk assessment was performed. Although important, the remote site could be down for several hours before a significant effect would be felt by the overall organization.
Too much of a good thing
The office and network staff overestimated the importance of the operation to the business and built a design almost four times as expensive as it needed to be, based on the cost to buy highly available equipment and twice as much of it. The security-risk team suggested a lower level of availability equipment and saved the organization money. The best practice was too much for the job.
There is a simple, facilitated procedure to do this, normally at one of the meetings that is already a part of the design and decision-making process. The National Institute of Standards and Technology 800-30 process says to identify threats and vulnerabilities and identify controls mitigating those risks already deployed ("current controls"). Keeping those in mind, estimate the likelihood of the threat and the impact of the exploit of the vulnerability. This defines the "risk".
The easiest way to do this is to make a list of all the threats and vulnerabilities. Most people who aren't accustomed to abstract risk concept tend to group threats together as a "bad thing that could happen".
Listing threats as one makes the procedure easier for IT and business to follow and provide valid input. Then, group similar things together and gain consensus on the final list.
What gets top billing?
The goal should be to have a reasonably sized list -- 10 to 50 is a good amount. For example "unauthorized access to a Web application" can catch all the hacking, exceeding authorized access, and looking at other information risks to a company. From this list, rate each one as high, medium or low for probability and impact. This should be fairly simple to do: most people intuitively know viruses occur frequently, and that natural disasters don't.
Use this list to gauge the amount of control you need. Obviously a high probability/high impact risk needs more control to bring it to a medium/medium, or a low/medium. Something that reduces a high/high to a low/low has normally reduced too much risk and cost too much. Use a simple chart to map the risk-reduction to the cost of the controls. A high-risk reduction impact that has a low cost should be implemented immediately.
For example, an internal firewall to control access to payroll and finance is critical for Sarbanes-Oxley Act compliance. However, a high cost/low reduction control, such as using similar firewalls to segment every server in the company, is probably a waste of money.
A successful IT professional leader should focus on how much risk needs to be alleviated, and how much will the various controls needed to do that cost. When you really do need to implement an additional control, this process will help you pick the least-expensive one.
As David Lynas, executive director of security organization The SABSA Institute, says, "Spend absolutely every penny you need to on security. . . but not a penny more."
David Lawson is VP and a director of the global security practice and facility security officer at Greenwich Technology Partners
- +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients? - +
Strategies for Dealing With IT Complexity 24/12/2007 10:30:47
Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Mitel Launches Simpler Unified Communications 2008-11-19 17:40:00+11
Symantec Security Products Shine in In-Depth Protection Reviews 2008-11-19 13:01:00+11
Digital Sense opens first stage of the world’s largest data centre complex in Brisbane 2008-11-19 13:00:00+11
RightNow Technologies Delivers RightNow November ’08 Plus New On Demand Enterprise Contact Centre Package 2008-11-19 12:00:00+11
Valorem uniquely deploys RSA SecurID for remote workforce management 2008-11-19 10:16:00+11
Understanding Email Marketing: A Guide for SMBs
Email marketing is often viewed as a marketers silver bullet. If used effectively, email campaigns will provide strong results for a limited spend each and every time. Download this white paper to discover how email marketing can work for you and your business.








