How to Manage Vulnerabilities of Information Systems to Security Incidents

How to Manage Vulnerabilities of Information Systems to Security Incidents thumbnail
Always consider potential vulnerability when creating your information technology plans.

Risk exists everywhere in the information technology world. Obviously, there is the risk of malicious attack from hackers, but there are often more likely to occur risks that are completely overlooked. User error can destroy or leak data, or even take down a system completely. Fires, floods and other natural disasters can wreak havoc on any network. While risk can never be completely eliminated, taking a systematic approach to evaluating and implementing basic network security can go a long way toward minimizing vulnerability and expediting recovery should an incident occur.

Instructions

    • 1

      Examine the physical security of your network. All critical data storage, servers and network equipment should be in secure rooms or closets. Only authorized information technology personnel should have access to these spaces. In addition, be sure the spaces have adequate sensors for fire and flooding, suppression systems and emergency backup power in case of a power loss.

    • 2

      Secure the perimeter of your network against outside vulnerabilities. Put border routers and firewalls with strong security policies anywhere your network touches an outside network, including the Internet. Be sure these are constantly monitored and set to send alerts to emails and cellular phones in case an intrusion is detected.

    • 3

      Install virus-scanning software on every computer in your network. While a good security policy prevents users from introducing outside software without written approval, the reality of the situation is that most users will still put disks and CDs from home into work computers. A good virus scanner on each computer will detect threats introduced internally quickly, making containment easier and minimizing impact.

    • 4

      Develop a good backup and recovery plan. Despite all the best planning and minimization of risk, incidents can occur. Minimizing the impact of these incidents depends on having good backups of critical data and a recovery plan in place. Data loss and downtime equate to dollars lost, sometimes millions per hour, so returning to full operation in the case of an incident is critical.

Related Searches:
  • Photo Credit man thinking about internet security image by patrimonio designs from Fotolia.com

Comments

You May Also Like

Related Ads

Featured