You are here: silicon.com > Software > Security Strategy

Security Strategy

MI5 chief says security is down to policy, policy and more policy

Whether it's your network or your nation there's no substitute for planning...

By Munir Kotadia

Published: 16 September 2003 16:37 GMT

An organisation can never be truly secure until it has developed and enforced a well prepared security policy, according to Dame Stella Rimington, former director general of MI5.

Rimington, who was a keynote speaker at the Gartner Security Conference in London on Monday, said companies should use the same principles that the secret service does in order to ensure secrets do not fall into the wrong hands.

"The principles of national security and commercial security are exactly the same," said Rimington, who admitted that different techniques are involved, but explained that, essentially, the most important thing is having a rock solid security policy that is enforced.

"It all comes down to sensibly applied security measures closely related to a realistic assessment of the threat. All protective security, including the security of information, is about assessing risk," she said.

According to Rimington, there are a number of questions that companies have to be able to answer before they can fully appreciate what they need to do and, more importantly, how to do it.

First, said Rimington, companies should calculate the true nature of the threat.

"Who is your enemy, what is their objective, what do they want to do to you, do they want to steal your secrets, goods, poach your staff, embarrass you in the press, take over your company or blow you up?" she asked.

She also warned against spending too much time and effort on protecting yourself from unlikely threats while more likely threats were ignored.

"Is the enemy capable of doing whatever they want to do -- is it a real threat? If they are, how are they going to go about it? Do you need to look after your documents, information on computer, telephone calls, people or goods?" Companies need to answer all these questions before they even start thinking about what they are going to do, or even what they can do to secure their systems, she added.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Security Operations Engineer

Follow standard practices and procedures to respond appropriately to external and internal threats Providing front line support for all information ...

Information Security Consultant

Assist in definition of the security architecture or related control measures to mitigate security risks. Knowledge of a variety technical security ...

Consultant

s budgetary and resource requirements.c) Research for projectsYou will undertake research for projects including: analysis of data from audits, ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: