|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Tackling security policy management By Chy Chuawiwat, ZDNet Australia April 30, 2003 URL: http://www.zdnet.com.au/insight/soa/Tackling-security-policy-management/0,139023731,120274097,00.htm
OPINION: Successful organisations need core IT security polices, as well as the means to monitor employee adherence. How can Australian organisations get it right? Each organisation needs to identify its specific areas of concern--whether it be to protect information, maximise operational effectiveness, minimise corporate liability or guard against damage to its reputation. From there enterprises can then figure out the most effective way of dealing with these concerns. This may involve hardware and software solutions, and also company-wide rules about appropriate usage and employee behaviour. To establish an e-mail policy companies must:
Large global organisations will probably find that a 'one size fits all' policy may not work for them. Laws vary between both states and countries, and each location may require its own version of the corporate policy. Many departments across locations--including HR, security, IT and legal--need to be consulted to define, document, maintain and enforce policies. E-mail policies and related procedures need to be distributed rapidly and reliably throughout the organisation, accompanied by a test program to gauge employee understanding and confirm acceptance. Setting up an IT security policy can be a daunting process, but it is one which Australian organisations should make sure they tackle. Chy Chuawiwat is managing director at security vendor Clearswift Asia Pacific. He can be contacted at Chy.Chuawiwat@clearswift.com.au
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |