\"Security Controls and the Business\" Please respond to the following: Discuss
ID: 3561613 • Letter: #
Question
"Security Controls and the Business" Please respond to the following: Discuss in your own words the importance of balancing security and business functionality. Determine why upper management buy-in for a security program is essential for the programs success and compliance of end users. Evaluate why administrative, technical, and physical controls need to be implemented in tandem for a security program to be effective and determine which of these control sets you believe is the most important. Justify your response.
Explanation / Answer
"Security Controls and the Business" Please respond to the following: Discuss in your own words the importance of balancing security and business functionality.
Basically, what this means is that while security controls are important to keep important proprietary and business critical information safe for a company, they also must be implemented in a manner that allows people to do their jobs and have the business operate effectively. I have seen some situations where this does not happen and the security controls in place are over stringent which impact workers and the business in an adverse way. At the same time, the opposite can also happen where the controls are not sufficient to keep data safe from hackers and company competitors. It is a critical balance that companies must establish as well as re-evaluate over time.
Determine why upper management buy-in for a security program is essential for the programs success and compliance of end users.
Like almost any other business project or standard, if the company leaders and management do not buy-in and support the program it will not work. Employees watch the company leaders and will pick up on this. When management demonstrates that this, then employees will not take the security program seriously and practice compliance. Whereas if management supports the program, employees will follow as well.
Evaluate why administrative, technical, and physical controls need to be implemented in tandem for a security program to be effective and determine which of these control sets you believe is the most important.
All must be in place for a company security program to work. For example, if administrative controls are in place (login, password, etc.) it will not help if physical controls like shredding company information before throwing it away, locking doors, etc are not in place. This also holds true for the technical controls. If administrative and physical controls exist, they will not help in establishing an overall secure environment when the technical controls are not in place.
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.