Security management Toolkit
Story: Don't blame 'stupid users' for data breaches
the Weakest link is ?
If they had an BS7799 or ISO 27000 security audit should prevent excessive permissions to junior staff. Implementing Role Based Accounting would help, but requires experience and knowledgeable staff to get it working. Selling the idea should be easy NOW that senior staff will have to start listening,but some of them cannot or will not under stand unless the outsourced IT company pays a penalty (BIG TIME) other wise the incentive is lost or not remembered.
If the staff are the week link then integrate the basic IT security into your annual Health and Safety tests done by ALL your staff. Ensure your HR departrment check all staff have completed the H&S, IT security, absic policy and compliance.
The policy should prevent silly events from happening, and staff awareness of what should NOT be done. but what about the mangers who break the policy and procedures and insists on the lowest cost or lowest work required. (Organ donor ?)
Full Talkback thread




