StudentShare
Contact Us
Sign In / Sign Up for FREE
Search
Go to advanced search...
Free

Business Management Technology: IT Security Management - Essay Example

Cite this document
Summary
"Business Management Technology: IT Security Management" paper argues that IT security management is very important for a business. Information is a key part of the business. IT security management means keeping the confidentiality, integrity, and availability of the data. …
Download full paper File format: .doc, available for editing
GRAB THE BEST PAPER93.5% of users find it useful
Business Management Technology: IT Security Management
Read Text Preview

Extract of sample "Business Management Technology: IT Security Management"

Introduction: In this era of technological advancement, IT security management is very important for any business or organization. Now almost all companies use IT and IT system for storing, retrieving and processing of business data and customer’s information. They do many simple transactions, business to business transactions and customer to business transitions through IT system. Some of them can be of confidential nature. Any type of the IT system failure will badly affect both the functioning and the goodwill of the company. Thus IT Security Management becomes very important for a company. Even computers and its software are very costly. And the data stored in the computer is more important and costly compared to the computer cost. So management and the employees who are working in the IT system should have a clear awareness about the importance if IT security management in business. The purpose of IT security management is “protect the company’s information assets from all threats, whether internal or external, deliberate or accidental, to ensure business continuity, minimize business damage, and maximize return on investments and business opportunities.” (Information Security Policy Statement: Objective. 2004, p.13). Review of literature: Review of literature on this topic is given here: Broad objectives of IT Security Management: CEO of the company gives approval for the Information Security Policy of a company. This policy includes confidentiality, honesty, and accessibility of the information. Information assets should meet all the needs of the regulatory authorities. Information security should be provided to all the staffs. There is an information security manager in a business or organization. Specific objectives of the IT Security Management: There should be physical security, and other types of security like Internet security must be provided. IT security management should include organizations, risk management, ownership, policy standards, procedures, support and action with due care. (Importance of Information Security Management). Organization:-IT security management should be applicable to all persons in the company. Every one should take the responsibility of their actions. They should understand and support the company’s requirements and sincerely work to full fill those requirements. Risk Management: - Risk means uncertainty or a loss. Most important type of risk is operational risk. It is occurred due to internal or external events. Main reason for this type of risk is either fraud or error. Operational risks from IT effect credit, strategic, reputation, market risk etc. To avoid these risks top management must measure, control and monitor the technology. In risk analysis all the difficulties and events faced by the company should be analyzed. These threats and events will badly affect the company’s strategic and operational environment. Some examples of events that could effect the business institution are security breaches, system failure, external events, technology investment mistake, system development and implementation problems and capacity shortage. Different types of security breaches are virus attack, hackers, unauthorized access etc. System failure includes hardware and software failure, internet problems, communication failure etc. External events are different types of calamities happening on in the earth like earthquake, flood, terrorist attack, fire, cyber attack etc. Technology investment mistake includes lack of proper platform, unclear requirement definition, mismatch with the current system etc. Development Implementation mistakes include misleading of management, shortage of time and manpower, programming errors and inefficiency of the system etc. Capacity shortage occurs mainly due to the lack of proper planning. After identifying the risk the organization immediately estimates the after effects of the risk. (Risk Identification and Assessment). Ownership: - Storing and retrieving of data, any modification or process in the data and the transferring of the data should be done by the controlling authority of the organization. Otherwise there is a possibility for loosing the data. So the authority has the responsibility for these activities. Policy standards and procedure:-A company must have its own policies, standards and procedure. It helps to improve the IT security. For example, many companies have website and almost all companies have E-mail address. To give maximum IT security, implement some rules for the company that its password is never too short and it must include numerical letters. There must be at least eight characters. Password for the E- mail ID should be changed every month. To enter into the company’s website a user name and password are essential. So a person who knows the user name and password can enter into the website. Others cannot login into the site. It also helps to improve the IT security of the business. Business should have a procedure to do any work especially works which are of confidential nature. Support:-For the support and monitoring of the day to day activities of the entire systems, there is a need for IT security management. It enriches the security of the business. Action with due care: - Every major activities and major decision making are done by the knowledge of the manager. Otherwise each and every department creates their own IT policies and it leads to a collision between each department and the management. (Importance of Information Security Management). Development of the core arguments Information is the core of a business. Information is stored in the IT system that is mainly in computers. So the security of the IT systems is very important for a business. Any type of breach in IT security may not be affordable by the firm. Loss of the critical data will badly affect the financial security and goodwill of the company. Some times its aftereffects cannot be recovered. Many companies share their data and information with other companies. For this they use Internet instead of paper documents. Major advantages of using Internet is that it is faster than any other methods and can send large volume of data at one time. But Internet also has some security problems. Hackers are the major problem. They may access the data and change the given details like catalog of the company, item list, price list, etc. Sometime they may destroy these details. In some cases they edit or demolish the company’s website. By this way hackers can redirect the company’s customer. They also collect the financial details of the company and use this information for committing frauds. So company should implement effective IT security management. Major security breaches occurred in almost all companies are the misuse of the login details. It is mainly done by the employees or by the cooperation of the employees. By this way unauthorized access of the confidential data is occurred. Another factor that affects the IT security is computer virus. They can alter the software used in the business. Some viruses delete the existing files. Some others slow down the working of the system or lead to the system crash. Many viruses spread rapidly. It affects the proper functioning of the business. To avoid this type of data loss, keep a hard copy back up daily and load anti virus software and update that as regularly as possible. To avoid the misuse of the login details by the staff, promote a policy of the company. The breaches by the staff occur mainly due to the lack on knowledge about the importance of IT security in the business. So give proper training to the employees about the importance of IT security in the business and how to react when any virus attack is identified. And give more training to the people who do the IT based job in the company. Set a limited number of people like network operator and administrator to access the system. Check their background and working experience thoroughly. (IT Security: The Basics). Some important IT security methods: According to Richard W. Boss some of the important IT security methods are Server:-An organization having more than one server must allocate a server room for keeping the servers. Arrange high security for this server room. The windows in that room should be barred. Check the electric circuit in the room strictly. Fire protection system is essential for this room. Excess heat will lead to the server downtime and sometime it may damage the system. So provide air conditioning system in this room and every cabinet should have cooling fan. There should be an alarming system which operates when the working of the cooling fan is disturbed and the room temperature is increased. Precaution against water damage is also essential. Do not allow any pipes on the ceiling of the server room. Abnormality in power supply is another reason for the server damage. The server room must have a UPS (Uninterrupted Power Supply) which supplies power to the servers when the power supply breaks down. Provide firewall protection to the server. Firewall will help to deter attackers. Keep back up every day. Network:-In Local Area Network (LAN) use hybrid topologies like star bus topology. It is a combination of different types of topologies. Many computers are connected to a hub. And more than one hub is connected to another hub. For the connecting, different machines use unshielded twisted pair or twisted pair fiber optic cable. It provides high security and speed. Clients:-Try to regularly update the antivirus software. Mainly E-mail attachments act as the carriers of the viruses. So employees in the organization should be careful in opening the E-mail attachments. Avoid the opening of unknown E-mail attachment. Also give proper guidance to the staffs about the usage of E-mail and the way how virus attacks the computer. (Boss 2002). According to Dr. Rossouw von Solms “Today, business partners need to link their computer systems for business reasons, but first want to receive some sort of proof that the other partner has got an adequate level of information security in place.” (Solms 1996, p.281-288). Otherwise they can’t transfer their business data and information smoothly. Now many organizations have a single or group of persons assigned to the IT security management. A business firm has many business partners. So they should confirm their IT security. Conclusion: From the above mentioned points it is clear that IT security management is very important for a business. Information is the key part of the business. IT security management means keeping the confidentiality, integrity and availability of the data. Confidentiality means to protect the secrete information from unauthorized access. Integrity means to protect the accuracy and completeness of the data. Availability means to ensure the accessibility of the data as required. For the proper IT security management, organization should apply some policies and procedure. IT security management has both internal and external importance. Its internal importance is that IT security is essential for the proper working of the business. That means for the proper working, business need accurate and complete data at the correct time. External importance of the IT security is that company’s products and services are established in the market and any unsatisfactory information supply leads to inefficient service. It is not good for a business. For these every people in the organization should have a clear awareness about the importance of the IT security management. (Cazemier, Overbeek and Louk 1999, p.9). According to Chris Mitchell “Information system security is the application of managerial and administrative procedures and technical and physical safeguards to ensure not only the confidentiality, integrity, and availability of information that is processed by an information system but also information system itself , together with its environment as well.” (Mitchell 2004, p.407). For providing IT security for a business there must have efficient security for the servers, network and clients. Moreover the business must have proper risk management. Risk management is very important in IT security management. For solving major risks like virus attack, install most efficient anti soft wares like Norton and MacAfee and up grade them properly. To avoid unauthorized access give guidelines to the staff and implement proper IT rules, regulations and policies in the company. Bibliography BOSS, Richard. W. (2002). Disaster Planning for Computer and Networks. [online]. Last accessed 04 March 2009 at: http://www.ala.org/ala/mgrps/divs/pla/plapublications/platechnotes/disasterplanning.cfm CAZEMIER, Jacques A., OVERBEEK, Paul L., and LOUK, M C. (1999). Security Management: Fundamentals of Information Security. [online]. The Stationery Office. P.9. Last accessed 04 March 2009 at: http://books.google.co.in/books?id=1ANBY4CEQ0cC&pg=PA1&dq=Importance+of+IT+security+in+business+management#PPA9,M1 Importance of Information Security Management. [online]. KeyItSolutions. Last accessed 04 March 2009 at: http://www.keyitsolutions.com/information_security_management.htm Information Security Policy Statement: Objective. (2004). [online]. Dti. P.13. Last accessed 04 March 2009 at: http://www.berr.gov.uk/files/file9981.pdf IT Security: The Basics. [online]. Business Link. Last accessed 04 March 2009 at: http://www.businesslink.gov.uk/bdotg/action/detail?type=RESOURCES&itemId=1075423269 MITCHELL, Chris. (2004). Security for Mobility: There is More than Just Security and Privacy Measures. [online]. IET. P.407. Last accessed 04 March 2009 at: http://books.google.co.in/books?id=Zw5l0YAWq68C&pg=PA406&dq=Importance+of+IT+security+in+business+management#PPA407,M1 Risk Identification and Assessment. [online]. Management. Last accessed 04 March 2009 at: http://www.ffiec.gov/ffiecinfobase/booklets/mang/07.html SOLMS, Rossouw. (1996). Information Security Management: The Second Generation. Computers and Security, 145 (4), 281-288. [online]. Science Direct. Last accessed 04 March 2009 at: http://www.sciencedirect.com/science?_ob=ArticleURL&_udi=B6V8G-3VV42CF-1&_user=10&_rdoc=1&_fmt=&_orig=search&_sort=d&view=c&_acct=C000050221&_version=1&_urlVersion=0&_userid=10&md5=b1310e1abdda2c98434d09fc2d178032   Read More
Cite this document
  • APA
  • MLA
  • CHICAGO
(“Business Management Technology Literature review: IT security Essay”, n.d.)
Business Management Technology Literature review: IT security Essay. Retrieved from https://studentshare.org/miscellaneous/1552283-business-management-technology-literature-review-it-security-management
(Business Management Technology Literature Review: IT Security Essay)
Business Management Technology Literature Review: IT Security Essay. https://studentshare.org/miscellaneous/1552283-business-management-technology-literature-review-it-security-management.
“Business Management Technology Literature Review: IT Security Essay”, n.d. https://studentshare.org/miscellaneous/1552283-business-management-technology-literature-review-it-security-management.
  • Cited: 0 times

CHECK THESE SAMPLES OF Business Management Technology: IT Security Management

Information Security Management Issues

The essay "Information security management Issues" analyzes the major disputable issues on the system of information security management.... Thus, an organized collection of procedures, people, and information technology (IT) structure that protects decisive systems and information, and secures them from inside as well as outside intimidations are known as information security management (ISM) (Sipior, & Ward, 2008), (Northern Illinois University, 2007) and (Grimaila, 2004)....
11 Pages (2750 words) Essay

Information Technology Security

The problem is it security.... It is said that operations management deals with decision making related to production processes to ensure that the resulting goods or services are produced according to specifications.... Effective project management means getting the right things done according to the planned schedule.... 1) Project management begins with planning.... Teamwork is an effective method in project management....
8 Pages (2000 words) Case Study

Network Security Principles

NETWORK security PRINCIPLES Network security Principles Author Author Affiliation Date Network security is a set of rules and regulations that a business organization must follow in order to protect its computer system.... At the present, network security is a major concern for each business in which computers are utilized to a great extent.... In this scenario, network security threat means that a competitor or a hacker can gain access to the sensitive or vital information, which can cause the entire business destruction or personal information related to a specific system or data loss....
3 Pages (750 words) Essay

Information Security Management

This paper ''Information security management'' takes a look at the security threats that an SME faces online and its need of information security management to tackle these threats.... This paper would take a look at the security threats that an SME faces online and its need of information security management to tackle these threats.... An effective Information security management allows businesses to implement various measures that would protect various data and assets that the business owns....
18 Pages (4500 words) Research Proposal

The Unification of Information Security Program Management and Project Management

A partner of Hurwitz and Associates, Fran Howarth, wrote an article about "The Convergence of Physical and it security.... The breakthrough of the new technology and the aim of any organization or enterprise to achieve development and better service have pushed the unification of Information Security Program management and Project management.... In light of the mentioned union, his paper will discuss the risks brought about by the new technology, the tasks to be dealt with in developing the Enterprise Information Security Program, and the adherence to executing risk management....
5 Pages (1250 words) Article

Analysis of Some of Main Aspects of the TRANSCORP Business

In this scenario, one of the main barriers in the case of any security management aspect is the cost and time-based aspects.... or the TRANSCORP Business in case of enhanced business and corporate security management, we need to take some enhanced security measures.... In this scenario, one of the fundamental measures is to establish an effective business security management policy.... In case of enhanced implementation of business security policy, we need to take care of all business operational areas those need to offer better business security management....
10 Pages (2500 words) Case Study

Information Technology Security Management and Its Impact on Business Success

"Information Technology security management and Its Impact on Business Success" paper designs and implements server protocols that will satisfy the business needs as well as maintain the security and integrity of the organization's critical and confidential data.... o produce a reHigh-risking the High-risk factors involved in it security manaHigh-risk recommend which-improvement.... To produce a report high-risk the high-risk factors involved in it security mana high-risk recommend ways of improvement....
12 Pages (3000 words) Thesis

The Information Security Management System - Conceptual Mapping

The paper 'The Information security management System – Conceptual Mapping' is a meaningful example of coursework on information technology.... The paper 'The Information security management System – Conceptual Mapping' is a meaningful example of coursework on information technology.... The paper 'The Information security management System – Conceptual Mapping' is a meaningful example of coursework on information technology....
6 Pages (1500 words) Coursework
sponsored ads
We use cookies to create the best experience for you. Keep on browsing if you are OK with that, or find out how to manage cookies.
Contact Us