Find White Papers
Home
About Us
List Your Papers
    
> Symantec.cloud > A risk assessment for your AUP

A risk assessment for your AUP

White Paper Published By: Symantec.cloud

Concerned about your existing AUP? Or are you looking to create a new usage policy from scratch? Either way, performing a risk assessment is a vital first step. If you don't identify the risks posed by email & web misuse in your organisation, then your AUP will not be fit for purpose & your company may still be exposed. Download this legal briefing & understand the importance of your risk assessment



Tags : 
messagelabs, symantec hosted services, aup, acceptable use policy, security risk assessment, information security, business continuity management, compliance

Symantec.cloud
Published:  Feb 12, 2010
Type:  White Paper
Length:  5 pages

WHITEPAPER
getting your a.u.p right
Step 1: assessing your risks
a legal briefing
Author: Jonathan NaylorBarristerJan 2010
www.messagelabs.com info@messagelabs.comWHITEPAPER
Introduction
If an Acceptable Use Policy (and a technical solution to enforce it) is the final part of a process that organisations must go through to minimise the risks they face to their corporate IT systems, the risk assessment must be the start of that process.
So how does an employer undertake such a risk assessment? What are the factors to be considered and how does this translate into the appropriate Policy and software solution? The aim of this short briefing document is to give employers some guidance on how to conduct this crucial step in the process of protecting the organisation from unnecessary risks.
What type of IT security risk assessment is suitable for your organisation?
Any organisation will need to consider what is most appropriate for the particular business, taking into account the nature of the employer and the specific threats that it faces. Will an informal "stop gap" review suffice; does the organisation require a more thorough and detailed assessment; or is it such a crucial area for this individual business (perhaps because it holds particularly sensitive data or has a very large number of employee IT users) that the organisation should outsource the assessment to an independent third party assessor?
In practice, how is the assessment going to be conducted? Should this be a formal process or merely an informal dialogue between senior management and the IT team? How will findings and recommendations be recorded and publicised? There are no set answers to these questions; the correct approach will vary depending on the specific business.
Why is a risk assessment needed?
Neglecting an IT security risk assessment can result in financial losses, organisational problems, customer relations issues or brand damage to the business. Key risks include employee misuse of corporate IT systems, loss of confidential/client data, denial of service attacks, viruses, disaster recovery issues, unauthorised access to systems and website security.
If an organisation frequently bids for public sector work, tendering requirements will often demand that details of its policies and procedures, including whether a risk analysis has been conducted, are disclosed.
Employers should also consider what steps they need to take to comply with legislation such as the Regulation of Investigatory Powers Act, the Data Protection Act and (if they are a public sector body) the Freedom of Information Act.
www.messagelabs.com info@messagelabs.comWHITEPAPER
Key elements to get right
In conducting any IT security risk assessment it is important to have both the understanding and the support of senior management. There also needs to be some form of training for employees so that they are aware both of the risks and the steps that can be taken to minimise those risks. Educating employees to view this not just as an employer denying them the opportunity to do what they want to do or "spying" on them, but rather ensuring that both the individual and the business are protected from unnecessary risk is a difficult, but important task.
Companies may wish to consider adoption of the British Standards on Information Security (the 7799 Standards) which form the basis of the International ISO 27000 Standards which are increasingly being used to structure security processes.
You should consider the scope of any risk assessment; which elements of the business need to be covered? There may be a further risk to be considered if functions within the business are being outsourced to third party service providers or agency contractors.
Key areas to cover are:
. Consider some of the possible threats that your organisation may face and record these in a Risk Register. The Register will then assist in formulating responses to the identified risks.
. What is the physical location of your IT systems? Does this present any particular risks?
. Has the business developed a Disaster Recovery/Business Continuity Plan?
. What are the arrangements for regular backup of information and secure storage?
. Does your organisation use a wireless network? Are there specific arrangements needed for ... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search