What are the top five high risk areas in a network operations environment?

What are the top five high risk areas in a network operations environment?

What would you say the top five high risk areas are in a network operations environment, for example business continuity, encryption, change control etc.?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

I'm not going to select the top five areas, because they are all needed. Let's take a closer look at why using your three examples:
  • If a company doesn't have a business continuity plan when a disaster occurs and assets are devastated, the company could go out of business.
  • If an organization doesn't encrypt sensitive data, it could be found guilty of non-compliance, or if the data fell into the wrong hands a company could end up in the headlines because a thief got a hold of your customer's personal identifiable information.
  • If an organization does not use change controls and changes are being made in an unauthorized manner, the company essentially loses money in operational costs, and this directly affects the stability of a corporate environment.

And, barring these three items are under control, if an organization doesn't implement proper wireless security then someone can use that avenue to carry out destruction. Likewise, if proper access controls aren't in place there is a possibility for fraud, and unauthorized access to sensitive data and company assets. Additionally, if security awareness training is not provided, then your organization may be non-compliant with one or two regulations, your users will not be informed on their responsibilities and you could be opening up your organization to potential civil suits.

There are just too many things that organizations need to carry out within their security program. Most organizations are very technology-centric and do a great job on implementing and maintaining firewalls and their perimeter security, but fall short on personnel security, data classification, access control and auditing. ,

So every organization has their own top five things that they need to work on. The industry as a whole is behind on many of the softer security skills (data classification, personnel security, risk management, process management, incident response, etc.), and if one piece is missed, it can negatively affect the company in different ways.

In my experience I have found that most organizations, and even security professionals, do not fully understand ALL of the components that make up a security program. Because organizations and people are so technology-centric they do not know how to properly integrate security into business processes. While, this is getting better over time because regulations are requiring organizations to do a lot more than just implement products, this is an evolutionary process and we are going through a lot of growing pains as an industry.

For more information

  • Attend our Identity and Access Management Security School and learn how to integrate security into the network.
  • Learn how to create a corporate security culture.
  • This was first published in September 2006

    Join the conversationComment

    Share
    Comments

      Results

      Contribute to the conversation

      All fields are required. Comments will appear at the bottom of the article.