A Primer on Information Security
October 2, 2002
By Michael Bruck
Q: I hear all this
talk about information security and insuring against intruders and perimeter
protection. What is it all really about, and what does all this tech talk mean?
A: Once you
understand what information security is all about, then you're ready to really
take steps toward securing your own information, networks and technology. So
let's take a closer look. According to Webster, insurance means "a means of
guaranteeing protection or safety."
Are your information systems and network set up to have guaranteed
protection? Many times information security is thought of as just another
insurance policy within a company. Can you justify the cost of your insurance
policy? You can if you have a claim. You can if something happens to the
protection of what is insured. A breach in your information security is best
insured against by putting the proper systems in place to prevent those
breaches.
According to the Department of Defense, "Information security is the
protection of information and information systems against unauthorized access or
modification of information, whether in storage, processing, or transit and
against denial of service to authorized users. Information security includes
those measures necessary to detect, document and counter such threats." In
today's world of increased security, it's comforting to see that our own
country's defense department has a good handle on information security. More
businesses today have the same handle, but too many businesses wait until an
incident happens before putting the proper systems in place.
Once you've gained a basic understanding of information security, you're in a
good place to put the necessary systems in place that will assure your peace of
mind. After all, isn't it better to do it now than to wait for that one breach
incident?
In researching this article, I looked at the top 10 Web sites related to the
word "security." The true intent was to see what type of security came at the
top. After all, our world is filled with security of all types; information
security ranks high in importance as it relates to company information. The
search pulled up B2B communications between networks, systems, applications and
users across the Internet, intranets and extranets.
There's a wealth of information out there that will help you understand your
own information security situation. Some companies don't do much about it
because they just don't know about it. Even though there are experts and managed
service partners available, some companies just don't know where to start.
Hopefully, this article will inspire you to get started (if you haven't
already).
|