Skip to Main Content

IT Security and the Importance of Policies and Procedures

When it comes to IT security, clearly defined and documented policies which can be translated into actionable and repeatable procedures.

Clearly documented and articulated policies leave no room for doubt as to what is expected and acceptable behavior. If your policy is vague and ambiguous, not only will employees be frustrated never being certain if they are compliant, but you will likely have multiple interpretations of how to implement the policy. Worse, you may wind up in litigation if you take disciplinary or civil action against someone violating policy based on their interpretation. Remember the old "Welcome Screen" of yore? Did companies really intend to "welcome" everyone, including hackers?

Policy is great, but limited. Policies need to be put into action, meaning translated into procedures which can be repeated and measured. If you have a policy that says everyone is required to have an ID and a password to access your systems, but you have no procedure defined around user ID provisioning that requires ID's be created with a password, then you will have ID's created without passwords someday, somehow, either by accident or via malicious intent. Procedures should drive behaviors, as in this example by the user ID provisioning team, to always create ID's with passwords, and those matching the password controls further defined in the policy (such as length, complexity, change interval, etc.). 

A policy that states this and clarifies the nature of the password gives a benchmark to know if you do or do not meet the policy. But having a procedure defined - based on the policy - that drives the behavior of those creating ID's gives you control of the situation.

If you're looking for managed IT services or professional IT services, contact Total BC Inc, today! 

How Managed IT Services Can Help Your Business

When it comes to managing your IT systems, the main problem becomes optimizing the staff and resources required to keep your operations up and running. This task not only requires strategic planning, but also the right leadership and skilled IT...

Common Business Phone Malfunctions

We all rely on our phones in one way or another. They offer instant access to news, family, friends, colleagues, and clients alike. Apps can also get you pretty much anything that you want. Next to computers, phones are like the life...

What Is Data Cabling?

Data Cabling: Carrying Information Between Computers & Network Equipment Most buildings feature electrical, phone and TV wiring. In recent decades, the fourth type of cabling has become increasingly common. Data cables carry information...

What Are The Benefits Of A Cloud Hosting System?

A growing number of businesses are implementing a cloud hosting system, and for good reason. Cloud hosting systems offer surprising benefits that help businesses protect crucial data from breaches and hardware failure. They are easier to access,...

Benefits of Managed IT Services

Whether you have a small or large business, it's important to carefully consider your IT needs and infrastructure. You may find that you don't have the resources or manpower to properly manage the necessary technologies. That's...

The Importance of Routine IT Maintenance

When an IT team decides to slow or shut down production for maintenance tasks, it might seem like a bottleneck. But just as a healthy human body requires regular checkups, a healthy organization requires regular IT maintenance. A...