New Year's Resolutions
Thu, 2007-12-27 20:55
Topic(s):

Given the season, I thought a set of New Year’s information security resolutions would be in order. I’m sure you have your own items, but here is my list:

  • Review and update our information security policy.
  • Calendar a complete test of our business continuity/disaster recovery plan. Update the plan as necessary.
  • Allocate funds and time this year to get a better handle on where and how data is used and stored within the enterprise.
  • Test and confirm the company’s litigation hold procedures to ensure relevant records, both hardcopy and electronic, are properly preserved in the event of a claim or litigation.
  • On completion of the foregoing tests and updates, review and revise, as appropriate, the company’s document retention policy.
  • Update the company’s technology, e-mail, and Internet policies to clearly address the latest areas of potential risk, including employee use of non-company-provided computers to access company systems (e.g., home computers), employee use of removable media (e.g., USB fobs and other portable storage devices), employee use of Web-based e-mail accounts, and employee installation of peer-to-peer networking software. Ensure employees are aware of any changes to the policies.
  • Provide additional training to relevant employees regarding the foregoing topics.
  • Read this blog once weekly.
  • Eat better and visit the gym on a regular basis.

 Happy Holidays to you all and best wishes for a very happy, secure, and prosperous New Year.

Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
* Denotes a required field
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast