Home > Security Tips > Network Security Tactics > How to increase security with a decreasing budget
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

How to increase security with a decreasing budget


Michael Cobb, Contributor
01.13.2009
Rating: -3.00- (out of 5)


Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


As we transition into what may be a bleak 2009, organizations everywhere will undoubtedly look at where they can cut costs or trim staff levels. Since IT security benefits have a mostly intangible effect on a corporation's bottom line, it is an area that, in many cases, may unfortunately be one of the first to get squeezed on budget. This is a real worry for many information security managers and staff alike, as I'm guessing security funds weren't frequently increased when times were good. In short, we're now likely to see the composition of already overstretched resources scaled back even further.

Don't miss need-to-know info!

Security pros can't afford to be the last to know. Sign up for email updates from SearchSecurity.com and you'll never be behind the curve!
Any budget cuts, however, shouldn't lead to a drop in security awareness. As a security manager, make high-level sponsorship of information security a priority within the organization to ensure continued compliance with security policies. Managers in other departments will be under a lot of pressure to get projects completed quickly and economically, but those needs shouldn't lead to a situation where security is compromised. Disasters can be avoided by checking that the ownership, responsibility and accountability for risk are made clear in policies and job descriptions. After all, senior management is legally responsible for compliance.

So how can infosec teams best tackle the tough times ahead? One issue that needs immediate attention, particularly if redundancies are likely within the IT department, is continuity. Unless skill and succession planning are put in place, current knowledge can leave when team members do. Does more than one person know how to maintain and troubleshoot the mail server? How many administrators really know how to configure the firewall? The separation of duties is important for security, but so is the rotation of duties. It ensures you're not reliant on just one member of staff for a particular skill -- a predicament that can often occur when the team is small, or if there's a lack of younger members being identified and trained up.

Human resources security policies should be reviewed to ensure they enforce a robust employee security lifecycle, including any external temporary workers, consultants and contractors. HR and IT departments must work closely when colleagues face changes of circumstance to ensure that access to IT resources and facilities always accurately reflects an employee's status and job function. For instance, procedures to ensure the return of swipe cards and ID badges are commonplace when an employee leaves an organization, but there are often gaps in managing logical security, such as the timely closing of a network account.

Merging physical and logical IT security teams
One way to improve overall security management without spending more is by merging the physical and logical security teams. With limited resources, it has always been difficult to enforce compliance at the desktop, given the nature of Post-it note passwords, unsecured laptops or USB keys and the like.

For more information

Integrating physical and logical security can bring many benefits to the enterprise, but a successful union isn't easy.

Learn more about when physical and logical security converge.
Why not make more use of the physical security teams who already patrol your office buildings and facilities? They can be easily trained to look for information security policy violations, such as cleared desks or properly secured server rooms, while on patrol and report back on any violations. Equipping night patrols with wireless detection devices, which cost a few hundred dollars at most, would enable them to look for rogue routers. Such steps would provide almost daily security compliance reviews. Employees would quickly become aware that the IT security team has a physical as well as a logical presence. The message could be reinforced by compulsory awareness training for violators. This approach gives real protection at a relatively low cost.

By working more closely with the physical security staff, the infosec team can also maximize the security potential of both sets of systems, protecting real and logical assets. For example, staff from many organizations may be required to carry an ID card. If the cards were also used for single sign-on, they would provide a centralized means to establish and enforce access policies for physical and logical resources using two-factor authentication. The two teams responsible for security can complement and reinforce each other's work and achieve better compliance with many policies and regulations, which is a worthwhile goal in its own right.

In 2009, every organization is going to be focused on being smarter, leaner and cheaper, so security is not going to be a top priority. It is important that infosec teams understand this, otherwise they are doomed to frustration and failure. However, by using the changes that inevitably occur during downsizing and restructures, there are many ways in which the importance of information security can be communicated. Change provides an opportunity to embed security into new business processes and a chance to eliminate a culture that allows people to bypass or omit it.

About the author:
Michael Cobb, CISSP-ISSAP is the founder and managing director of Cobweb Applications Ltd., a consultancy that offers IT training and support in data security and analysis. He co-authored the book IIS Security and has written numerous technical articles for leading IT publications. Mike is the guest instructor for several SearchSecurity.com Security Schools and, as a SearchSecurity.com site expert, answers user questions on application security and platform security.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Emerging Information Security Threats,   Information Security Policies, Procedures and Guidelines,   Information Security Management,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Network Security Tactics
How to prepare for a secure network hardware upgrade
Preventing SQL injection attacks: A network admin's perspective
Screencast: How to launch an OpenVAS scan
Wireless network guidelines for PCI DSS compliance
Aligning network security with business priorities
Scanning with N-Stalker offers basic Web application security assessment
Lifecycle of a network security vulnerability
Screencast: BackTrack 4 offers an arsenal of penetration testing tools
Network access control technology: Over-hyped or underused?
Screencast: Smoothwall offers firewall defense in lean times

Emerging Information Security Threats
Modern malware, stealthy botnets, adapt quickly, expert says
New ransomware Trojan pushes victims to buy software
Bruce Schneier on outsourcing, awareness training
US-CERT warns of BlackBerry snooping software
Marcus Ranum on cyberwarfare, infosec careers
Researchers find thousands of flawed embedded devices
Enterprise botnets contain thousands of malware variants
Nuke and pave to eradicate botnets
Rand study urges caution on cyberwarfare attacks
Hathaway joins Harvard to contribute to DOD project

Information Security Policies, Procedures and Guidelines
Essential guide: Pandemic planning for H1N1
Whitelists, SaaS modify traditional security, tackle flaws
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Reuters: Obama ready to select cyber security czar
How a corporate Twitter policy can combat social network threats
Should enterprises be concerned with Twitter in the workplace?
Information security management hype: Debunking best practices
Data breach avoidance begins with security basics, panel says
Expert: Information security spending often restricts innovation
GAO report cites government weaknesses, data leakage

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
DNS rebinding attack  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
phlashing  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
pulsing zombie  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts