Home > Ask the Security Experts > Questions & Answers > Do personal issues within a company pose a risk to the enterprise?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Do personal issues within a company pose a risk to the enterprise?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 30 April 2007
Does a personal bankruptcy of a member of the senior financial staff pose a significant risk to the enterprise? What policies should be in place to deal with such a scenario?

>
EXPERT RESPONSE
Any personal issues create potential risks in an enterprise. The employee could be distraught; he/she could be in desperate financial straits and do things to endanger your enterprise. This isn't as much of a security issue as it is an HR issue. Let's discuss the HR issues first. Consider getting the employee counseling. Of course, you don't have to, but you should. In fact, unless you are small corporation of less then 25 employees, an employee assistance program should be a standard benefit. Employees are the lifeblood of a business, and the enterprise needs to support them -- especially in times of need.

From a risk management standpoint, assuming the person is stable, it would be advisable to keep a relatively close eye on what they are doing for a period of time. Again, desperate times tend to result in desperate measures. You never want to assume that people (especially senior people) are going to do the wrong thing, but you need to be cautious and have checks and balances to rule out any foul play.

What should be done exactly? Examine the Sarbanes-Oxley Act, which focuses on strong financial controls. Now, I'm not saying go and get fully SOX compliant when there may be no need to do so, but make sure you have adequate controls in place and a proper separation of duties. It's also a good idea to close the books for a period of time every month to make sure you don't have disappearing assets. Doing an off-cycle audit is another precaution that can prove to be beneficial. Maybe some of these things are overkill, but the point is to make sure you have the proper instrumentation in place to know when there's a problem.

From a policies standpoint, it's about communicating company expectations to employees. I don't see any need for action here, since your employee handbook and other policies should spell out acceptable behavior and ramifications for violations.

What can't be minimized are the softer issues of employee support. A personal bankruptcy is one of the most stressful things that can happen to a person. If you can head off any issues at the pass by proactively offering support and counsel, small costs now will pay huge dividends later as these kinds of actions really engender a lot of loyalty on the employee base.

For more information:

  • Improve your ability to measure information systems risk with these three techniques.
  • Learn why metrics are the key to measuring security.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Risk Assessment and Analysis
    Data risks take shine off Google Chrome
    PCI is about eliminating data, not securing it, former QSA says.
    Security visualization helps make log files work
    Unified communications trigger data leakage dangers, survey finds
    CIO role could shift toward data quality, says IBM group
    Security data lapses hamper researchers
    Panel: IT governance, risk and compliance program helps reduce expenses
    Like MLB scouts, IT security pros are turning to metrics
    Google shares struggle to manage security complexities
    GRC Tools Help Manage Regulations

    Risk Management Metrics and Measuring Risk
    Consensus Controls project aims to set benchmarks for compliance
    CIS takes the measure of information security
    Security of customer data, IP sustains security budgets
    Security visualization helps make log files work
    Security data lapses hamper researchers
    Next wave of security will be defined by metrics, analysts say
    Like MLB scouts, IT security pros are turning to metrics
    Interview: Financial Services CISO David Pollino
    Failure mode and effects analysis: Process and system risk assessment
    The pros and cons of data breach insurance

    Creating a Security Culture
    How to get information security buy-in from the executive team
    Sound compliance policies, practices reduce legal costs
    Can home PCs provide a way for viruses and spyware to enter a corporate LAN?
    Unified communications trigger data leakage dangers, survey finds
    Security Awareness Training Essential Part of Infosec Program
    Societe Generale bolsters internal controls, discovers second insider
    Companies still monitoring email manually, survey finds
    Trading firms rethink risk strategy
    I am concerned that a former employee will utilize corporate information in a malicious way.
    Security, Privacy Offices Must Combine Resources

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    risk analysis  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts