preview

The Need for Information Security Management for Small to Medium Size Enterprises

Best Essays

The Need for Information Security Management for Small to Medium Size Enterprises
ICT 357 Information Security Management
Leong Yuan Zhang
31741147
Trimester 1
Murdoch University

Contents Abstract 2 Introduction 2 Justifying The Need for Sound Information Security in Any Organisation 2 Linking Business Objectives with Security 3 Incident Response Management and Disaster Recovery 4 Mobile Device Security Managment 5 Biometric Security Devices and Their Use 6 Ethical Issues in Information Security Management 7 Security Training and Education 7 Defending Against Internet-Based Attacks 8 Industrial Espionage and Business Intelligence Gathering 9 Personnel Issues in Information Security 9 Physical Security Issues in Information …show more content…

Despite that, most organisations do at least have some form of basic security in the form of anti-virus softwares. Other types of security software like firewall or authentication software/hardware are considerably less popular; perhaps due to the additional complexity of having to install and configure them for the organisation usage (ABS, 2003).

Linking Business Objectives with Security

Security can impact a company's profitability in both positive or negative ways. It fully depends on how it is being controlled, too little will not be enough while too much may cause bottlenecks within the company internal processes. One example would be background checks on possible new employees. At times, the duration of the check may take longer than the period of employment, especially when hiring temp staff to cover short term. In their book, Christian Byrnes and Paul E. Proctor argues that to eliminate the last 20% of risk that might occur would inversely required 80% more money to implement which can be seen in Figure 1.

Figure 1

It is common practice in large organisations to organise computer security around technologies, with a dedicated department running the show alongside the IT department. However computer security should be more business oriented as it is easier to achieve the security targets if good business practices are being followed. For SMEs, it is also far easier to

Get Access