Home > CIO Midmarket Briefings > Master data management: The art of managing data > Execution: Making master data management work > Frameworks just part of security plan
Briefings: Master data management: The art of managing data:
EMAIL THIS
 START   STRATEGY   EXECUTION   TOOLS AND TECHNOLOGY   
Execution: Making master data management work

<< PREVIOUS | NEXT >>: Seven master data management best practices
COLUMN

Frameworks just part of security plan

By Mike Rothman
27 Aug 2007 | SearchCIO-Midmarket.com


Technology news and tips for midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Compliance has been top of mind for most organizations during the past few years, although many small and medium-sized businesses (SMBs) have been able to skirt the heavy lifting that large, public companies must handle. Yet with the emergence of the Payment Card Industry (PCI) Data Security Standard, compliance is front and center for all organizations. Many SMB technologists get analysis paralysis when considering what they need to do to stay on the right side of the compliance Gods.

More on frameworks
ITIL at SMBs challenging but rewarding

ITIL, a data center's yellow brick road

So here is the $64,000 question -- how do you get to a strong security posture? There are a number of security frameworks that will set the foundation for a security program.

The frameworks

There are two leading frameworks that will help define at least the categories of assets and controls that need to be implemented in a comprehensive security environment:

  • ISO 27001: This ISO 17799 standard successor "provide[s] a model for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an Information Security Management System" (source). It uses the plan-do-check-act model.
  • CobiT: A set of best practices, measures and other methods for information security -- defined by the IT Governance Institute and the Information Systems and Audit Control Association.

These frameworks are very broad and very extensive, yet not really specific. Even though each lays out a vision of broad enterprise security, there are a lot of ways to get there. Thus, the framework is a start but isn't going to give you a step-by-step cookbook for what needs to be done.

Unfortunately that's pretty consistent with any discussion of frameworks. I haven't found a way to avoid doing the hard work to figure out what needs to be protected before building a plan to get there. In reality, the breadth of the framework is usually overkill for most organizations.

If you are publicly traded, CobiT will be a good place to start because many Sarbanes-Oxley Act auditors tend to have a rather strong grounding with CobiT. Likewise, if your organization has embraced ISO certification (like ISO 9001 for quality), then the ISO 27001 framework could make sense.

The plan

I always opt on the side of doing things, rather than just planning them. Sure you need a structured and a programmatic approach, but you can't sell an auditor on a framework. So here is a six-step approach to making some good, initial progress on your security program.

  1. Establish priorities. Get out from behind your desk and go talk to the senior executives in your business. Figure out what is important to them. Which systems do they think are critical to your organization? Which business processes, if affected, would cost them their jobs?
  2. Set a baseline. Do a penetration test or a risk assessment. Identify holes big enough to drive a supertanker through, and then use that baseline to both set the bar and show progress towards that bar.
  3. Triage. Fix those gaping holes and do it now. If you discover you've already been compromised, fix that and then put a plan in place to make sure it doesn't happen again.
  4. Plan. Build a plan to achieve your objectives. This will involve building a high-level security architecture and then a funding request to get the resources implemented.
  5. Operate your environment. A lot goes into operating a secure environment, but the most important thing to focus on is how you determine something is wrong. Since we have no idea where the next attack is coming from, you had better be able to react faster to possible issues.
  6. Document. Make sure anything you do can be documented and that you can substantiate any of the controls and/or processes you have in place to identify security issues. Auditors like reports (or so I've heard).

Sounds easy, right? Of course it's not. But you need to start somewhere, and most SMBs should opt for quick and dirty, rather than heavy and comprehensive. Once you have a base level of protection in place, you can get fancy and look at a larger framework.

Mike Rothman is president and principal analyst of Security Incite, an industry analyst firm in Atlanta, and author of The Pragmatic CSO: 12 Steps to Being a Security Master. Get more information about The Pragmatic CSO at www.pragmaticcso.com, read Rothman's blog at http://blog.securityincite.com, or reach him via email at mike.rothman (at) securityincite (dot) com.



Tags: Execution: Making master data management workInformation security management for the midmarketSecurity tools for the midmarketSecurity for the midmarketVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


<< PREVIOUS | NEXT >>: Seven master data management best practices
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
Execution: Making master data management work
Master data management syncs distributor's supply catalog
Virtualization as a data center management strategy: Videocast
New security tools best left to big companies, not SMBs
Seven master data management best practices

Information security management for the midmarket
Droid does, but will IT support it?
Information security program revamp adds outsourcer oversight and more
From data breaches to risk management frameworks: Test your knowledge
The challenge of managing risk when IT budgets tighten
Why cybersecurity awareness is everyone's responsibility
Information technology management e-book downloads for midmarket CIOs
10 must-have steps for an effective SMB information security program
Your IT security budget: How to get more bang for the buck
Using key risk indicators to sell your information security program
IT security spending a bright spot in '09, with more growth predicted

Security tools for the midmarket
Why CIOs need to get real about identity and access management in 2010
Free risk management tools and resources for the enterprise
IT security spending a bright spot in '09, with more growth predicted
Security and risk management in the midmarket
Identity and access management planning guide for the midmarket
A CIO's advice for implementing single sign-on solutions
Options for outsourcing security grow, offer IT budget savings
Network access control: Pointers for getting the knack of NAC
Unified communications: Securing access to OCS
Unified communications security: How safe is it?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Midmarket CIO Technology Advisor
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts