Security Controls

Security Controls

Security Controls Jonathan Poland

IT security controls are measures that are implemented in order to reduce security risks. These controls may be identified through security audits or as part of projects and continuous improvement efforts. They can be implemented as a matter of process, procedure, or automation, and are designed to protect against potential security threats or vulnerabilities.

There are many different types of IT security controls that can be implemented, including technical controls such as firewalls and antivirus software, as well as administrative controls such as security policies and employee training programs. These controls are often tailored to the specific needs and risks of an organization, and may be adjusted over time as the security landscape evolves.

Effective IT security controls are essential for protecting an organization’s assets, including sensitive data, systems, and networks. They can help to prevent data breaches, cyber attacks, and other security incidents, and are an important part of any organization’s overall risk management strategy. It is important to regularly review and update IT security controls in order to ensure that they are effective and aligned with the changing needs of the organization. The following are illustrative examples of IT security controls.

Authentication

Employees are required to pass multi factor authentication before gaining access to offices.

Audit Trail

A web server records IP addresses and URLs for each access and retains such information for a period of time as an audit trail.

Training

Employees are trained in defensing computing on an annual basis.

Peer Review

Design changes to a critical system require a secure code review.

Communication

Employees are prohibited from attaching documents to internal emails as they can easily be misaddressed. Instead, employees send a link to a document management system that offers authentication and authorization.

Incident Management

Any employee who loses an electronic device that has been used for work is required to report an incident immediately.

Cryptography

Data in storage is encrypted on all devices.

Passwords

Systems perform validation to ensure employees choose strong passwords.

Processes

An IT governance process reviews security incidents on a monthly basis.

Automation

A website places a three hour freeze on a customer’s account if they get their password wrong five times. This dramatically reduces the potential for brute force attacks.

Configuration Management

Changes to firewall rules require an approved change request.

Security Testing

Major system software releases are required to undergo security testing.

What is Design Risk? Jonathan Poland

What is Design Risk?

Design risk refers to the potential negative consequences that a business may face as a result of problems or issues…

What is Baseline? Jonathan Poland

What is Baseline?

A baseline is a reference point or starting point that represents the status or condition of something at a specific…

Vertical Integration Jonathan Poland

Vertical Integration

Vertical integration is when a single company owns multiple levels or all of its supply chain.

Niche vs Segment Jonathan Poland

Niche vs Segment

A niche is a specific, identifiable group of customers who have unique needs and preferences that are not shared by…

Risk Probability Jonathan Poland

Risk Probability

Risk probability refers to the likelihood that a particular risk will occur. It is an important element of risk analysis,…

Project Stakeholder Jonathan Poland

Project Stakeholder

A stakeholder is anyone or any group that is impacted by a project. This includes individuals or teams who are…

Workload Automation Jonathan Poland

Workload Automation

Workload automation is the process of automating the execution of routine tasks and processes in a business environment. It involves…

Comparative Risk Jonathan Poland

Comparative Risk

Comparative risk is a method of evaluating and comparing the potential impacts and likelihood of different risks. It is used…

External Risk Jonathan Poland

External Risk

An external risk is a type of risk that is outside of your control and cannot be influenced or managed…

Learn More

Examples of Capital Intensive Jonathan Poland

Examples of Capital Intensive

An industry, organization, or activity that is capital intensive requires a large amount of fixed capital, such as buildings and…

What is the Snob Effect? Jonathan Poland

What is the Snob Effect?

The snob effect refers to the phenomenon of a brand losing its prestige and exclusivity as it becomes more widely…

Data Infrastructure Jonathan Poland

Data Infrastructure

Data infrastructure refers to the hardware, software, and network resources that support the collection, storage, processing, and analysis of data.…

Request for Proposal Jonathan Poland

Request for Proposal

An RFP (request for proposal) is a document that asks suppliers to provide a detailed proposal for a supply contract.…

What Is Requirements Quality? Jonathan Poland

What Is Requirements Quality?

Requirements quality refers to the extent to which the requirements for a project align with the business goals and support…

Key Employees Jonathan Poland

Key Employees

Key employees, or key personnel, are individuals who possess unique skills, knowledge, or connections that make their prolonged absence or…

Tactical Risk Jonathan Poland

Tactical Risk

Tactical risk refers to the potential for losses due to changes in business conditions in real-time. Tactics differ from strategy…

Barriers to Entry Jonathan Poland

Barriers to Entry

Barriers to entry refer to factors that make it difficult for new companies to enter a particular market. These barriers…

Call To Action Jonathan Poland

Call To Action

A call to action (CTA) is a phrase or statement that is used to encourage a specific response or action…