enterprisesecuritymag

MAY 2023ENTERPRISE SECURITY| | 9patching operating systems, configuring multi-factor authentication, and backup data.Other technology essentials are endpoint protection (EPP), network firewalls, secure email gateway (SEG), and virtual private networks (VPN) with remote access management. Disaster Recovery (DR) configuration, strategy, and procedure as well as a well-planned backup strategy are other strong points for businesses, especially with noticeable on-premises IT assets.In terms of processes, it is vital to formalise IT Security policies, work procedures, and guidelines. This will require respective user education, focusing on people's IT security awareness training, ideally with tests and simulations. Approval of IT security policies by the CEO will also engage executive leadership support and get more compliance from all users.It is hard to imagine any medium business surviving against the modern threat landscape without having these above essential controls implemented. Even if some of them are not in place or don't cover 100 percent of IT assets and users, it is pretty much a matter of time before a cybersecurity incident happens. Using Recommended ControlsBesides essentials, it is also recommended to invest in data leak prevention (DLP), secure web gateway (SWG), cloud access security broker (CASB), and vulnerability management (VM) controls. Processes could benefit from a formalised incident response (IR) plan, periodic IT Security penetration tests, and third-party security assessments. Access to a professional virtual Chief Information Security Manager (vCISO) is also a prudent measure.These controls help to address more sophisticated threats or decrease the severity of incidents if they happen.Advanced ControlsIn case a business is a high-value and has low-risk tolerance, more advanced IT Security controls would include security information and event management (SIEM), managed detection and response (MDR) delivered by a managed security services provider (MSSP), Encryption of data at rest, cloud access posture management (CAPM), especially for cloud-hosted IT Assets.An independent IT security assessment conducted by a professional assessor could help to highlight weak spots or define IT Security strategy. Businesses can assess their IT Security posture against the most popular cyber security frameworks, like ISO 27001 standard (Information Security Management System) or the National Institute of Standards and Technology (NIST - U.S. Department of Commerce).If a business invests in the development of its business applications, these efforts should be respectively covered by its application security controls. Though this aspect is outside of the scope of this article.As the closing remarks, IT Security is not a point-in-time static state, but a journey, constantly reviewing all the above-mentioned threats, controls, and challenges. Once implemented, many of these controls require daily, monthly, quarterly, or annual operations, maintenance, or reviews. Delivered either by in-house staff, or outsourced to contracted MSSP, IT Security is an aspect of survival for many modern businesses, and this trend is only increasing.The adversaries need to succeed only once out of endless attempts when security measures should always be on top. And as technologies are now used by every business user, likewise, IT security is everyone's responsibility.Stay safe! ESIT SECURITY IS NOT A POINT IN TIME STATIC STATE, BUT A JOURNEY, CONSTANTLY REVIEWING ALL ABOVE-MENTIONED THREATS, CONTROLS, AND CHALLENGES
< Page 8 | Page 10 >