Over the last decade, e-mail and the Internet have transformed business practices, communications, and data exchange. However, as the flow of information has increased so have the threats to organizations relying on the systems that manage that information.In today’s business world, it is essential for information security policies to be developed as a consistent element of the organization’s overall workplace security policy so that detailed procedures are in place to respond to all security challenges. Too often the importance of developing and implementing information security policies, and training employees in information security procedures, is overlooked. An organization’s failure to secure its information can have serious business consequences such as financial losses, data loss, network downtime, lost productivity, and negative publicity. The next few paragraphs will review internal and external information security threats and ways to safeguard your company from them through the implementation of information security policies.
According to an annual survey by the FBI and the CSI, unauthorized access by insiders and insider misuse of Internet access are the leading source of computer crime and information security breaches. Keeping network resources and data safe from threats such as intruders and human error is critical. The Computer Emergency Response Team/Coordination Center (CERT/CC), an Internet security institution and part of Carnegie Mellon University, estimates that 60 percent or more of internal security problems they review are due to poorly chosen passwords. A June 2002 survey by the UK online bank Egg notes that the most common and easily hacked into passwords consisted of:
- 23% child’s name
- 19% partner’s name
- 12% birthdays
- 9% soccer team
- 9% celebrities and bands
- 9% favorite places
- 8% own name
- 8% pet’s name
Because of these simple to solve passwords, employees should be encouraged to change them to something that cannot easily be guessed. Companies should also put in place effective security plans that address password protection, training of employees on information security procedures, and enforcement of the policies. Key elements of a comprehensive security plan include:
- Protection against viruses: anti-virus software, employee training and so on
- Password protection: effective and enforced password policies and procedures
- Access control: only certain users are allowed to access a computer resource or physical area
- User authentication: verification that a user is who they claim to be
All of these precautions can help reduce and/or eliminate the majority of internal security problems.
From an external standpoint, hackers and intruders aim to gain control of a computer or computer network to launch attacks against other systems, or to obtain information from that computer such as credit card payment details, customer lists, and other confidential information. Any computer connected to the Internet is a potential target for cyber-criminals, also known as cyber-terrorists.
Hackers obtain control of a computer by identifying vulnerabilities, or holes, in the software. For example, a hacker may plant a virus to disrupt your system. To counteract cyber-criminals, software manufacturers work to identify the vulnerability and develop patches for these holes, but ultimately, it is up to the user or IT department to obtain and install the patch. According to CERT/CC, the majority of computer breaches could have been prevented if he correct patches and security upgrades had been installed. Once in control of a computer, however, a hacker can:
- Hide their true location, which could be anywhere from next door to another continent, to attack other computer systems (government, corporate systems)
- Observe and record your actions
- Control software, hardware, and other critical systems.
Another form of cyber-attack is denial of service. These attacks work by causing computers and networks to process so much data that they stop responding. The latest security patches from software providers are able to prevent most types of denial of service attacks.
To help prevent internal and external information security failures, the single most important safeguard is the development, implementation, and enforcement of an effective information security policy. The security policy is a document or set of documents that describes the security controls to be implemented in and organization, and provides a foundation for establishing a secure environment. The following basic steps for developing a security policy are recommended:
- Establish a security policy development team to include representatives (for example include employees from senior management, information systems management, security/loss prevention, legal, and/or human resources)
- Determine the policy administrator responsible for updating, revising, and most importantly enforcing the policy
- Classify systems: conduct an inventory of all systems and determine how they are being used in the organization
- Determine security priorities for each system: for example, for a Web server, the priority might be to limit access to only Hyper Text Transfer Protocol (HTTP) connections
- Assign risk factors: understand what the risks are if the policy is not followed, the risk could be disabling of corporate e-mail
- Define acceptable and unacceptable activities: for example, an acceptable activity is to make sure anti-virus software is installed on all workstations. An unacceptable activity is to open attachments from unknown sources. Defining these standards is one of the most essential elements of a security policy.
- Provide security awareness training: train all employees on the security policy, including what the policies are, where they are located and why following them is important.
The security policy should also address specific issues such as:
- Access control:
- Who has access to the system and the information on the system
- Levels of access required for different roles within the organization
- Screening for individuals with high levels of access
- Procedures for revoking access to the system
- User responsibilities in terms of:
- Protecting information they create, use, and have access to
- What users can and cannot do (files they can access, files they can download and so on)
- Passwords (frequency/type of change and so on)
- Levels of acceptable e-mail and Internet use
- Levels of acceptable non-business use of IT systems
- Securing confidential information
- Installation or use of unauthorized software
- Definitions of unacceptable use
- Password policies and procedures
- Back-up procedures and testing
- Systems monitoring
- What constitutes a security incident, for instance:
- Intentional disruption or denial of service
- Unauthorized use of the system
- Unauthorized changes to software or hardware configurations
- Unauthorized attempts to gain access to the system
- Incident response procedures
- Employee training (type and frequency, content, and so on)
- Policy updating and review procedures
Once the security policy is developed, all employees should become familiar with and understand the policy. When the policy is implemented and employees are trained, organizations will be ready to face any and all internal and external information security threats preventing any computer security failures to occur.
Information for this article was taken from BOMI’s brand-new product—Jane’s Property & Facility Manager’s Workplace Security Handbook. To order your copy today, please call 1-800-235-BOMI (2664).

