Establish a security budget so that from year to year an organization has the finances necessary to deal with security threats as they occur but also take measures to prevent security issues (Shimonski, 2005; Garcia, 2000).
Create a task force that can respond successfully and expediently to security emergencies (Shimonski, 2005). Along these lines a security breech plan of action should be developed and all employee informed of the proper steps to take if a security breech occurs.
Establish a recovery plan that will help protect assets. This should include establishing back up so a company has somewhere to go and can restore systems should an attack occur within an organizational structure (Shimonski, 2005; Sampson, 1992).
Sampson (1992) suggests the following steps for protecting data and organizational assets: (1) analyzing potential business risks, (2) protecting revenues from current or future losses, (3) reducing or removing an organizations exposure to risk and (4) filing claims or prosecuting any criminal actions that do occur within the workplace (p. 17).
Sampson (1992) suggest that organizations protect themselves from the following threats: (1) Catastrophes (external), (2) electrical power problems (external) and (3) computer crimes and viruses (internal and external threats) (p. 21).
Organizations must also work to decide whether potential threats are low probability or high probability within the organization (Grassie, 2000). This will enhance the organizations ability to manage threats. High consequence and high probability threats are the most important to manage as assets are most at risk from these threats (Grassie, 2000). On the same notes security managers shouldn't necessarily disregards high consequence but low probability threats unless the threat source is truly unlikely to affect an organization (Grassie, 2000).
Garcia (2000) suggests that organization must first (1) identify assets, including physical and intangible assets within the organization, (2) then decide what assets require what levels of protection based on the asset value, (3) next decide what the probability of an attack is, (4) identify what the consequence of a loss may be, (5) identify high consequence events and then (6) develop a risk management program that takes into consideration all of these factors (Garcia, 44). One way organizations can effectively manage threats is by creating a matrix to enable security teams to graphically review all assets and threats and determine how resources are best allocated (Garcia, 2000).
How Do Natural Threats Pose A Risk
Natural disasters pose just as much risk to organizations as man created threats (Sampson, 1992). Flood, fire, hurricanes and other natural disasters can result in serious damage to an organizations computer system, database and paper records (Sampson, 1992). Whereas an organization can take steps to prevent an external hacker from accessing their computer system, it is much more difficult to predict natural threats within an organization context.
Natural disasters can also have a domino effect enabling opportunists or hackers to penetrate a system. For example, fiber optic cables lost in a storm or power outages can allow computer viruses to attack (Sampson, 1992). To help mitigate such natural disasters it is vital that organizations prepare disaster mitigation or relief plans to address the heavy losses that may occur in the event catastrophe occurs (Sampson, 1992). Most government agencies and financial institutions already require an emergency disaster plan be in place in the event a natural disaster occurs (Sampson, 1992). The focus of the plan should be ensuring that an organization can continue to operate despite a catastrophic event; protection may include adequate insurance coverage and obtaining back up records (Sampson, 1992).
Other threats an organization must consider include catastrophic threats that may result from terrorist attacks (Grassie, 2000). While this is more often a concern among government agencies and financial institutions, all businesses should be aware of the potential for terrorist threats, which can "dramatically change the outcome of risk analysis" (Grassie, 2000).
Best Measures to Protect Assets
Schwartz (2003) suggests that an organizations information assets are the most important to protect because an organizations bottom line success is "linked to these information assets" (163). Further he suggests that any given technology is supported or "described by" information assets and this reliance on information assets in itself may pose security threats (Schwartz, 163).
Technology breakthroughs are occurring daily that often undermine previous measures to protect information assets, thus it is not enough for an organization to adopt the latest technology (Schwartz, 2003). Rather, an organization must work toward continuous improvements, which will result in ever evolving measures to ensure organizational security over time.
To protect human assets within the organization a corporation must also engage in cultural security measures. Culture...
Threats to Ownership and Copyright of Intellectual Property The intellectual property (IP) is defined as an original creative work, which may be tangible or intangible form legally protected by law. (Raman, 2004). The intellectual properties include the rights to scientific, artistic and literary works. Moreover, IP covers the invention of human endeavor, scientific discoveries, and industrial design. A current revolution of information technology has made IPs the greatest assets of assets.
According to an article entitled "Three Vulnerability Assessment Tools Put to the Test" Vulnerability assessment systems scan operating systems and applications for potential problems, such as the use of default passwords or configurations and open ports. This can give administrators a head start in fixing problems and will, hopefully, let IT organizations more effectively beat bad guys to the punch." The above factors are only true when vulnerability systems find all
assets an organization owns and manages. It will also look at the process and effectiveness of creating organizations' inventory with the main aim of having an effective daily system management and to for security of the organizations' assets. It is imperative that an organization has the records of all of it assets. One of the most fundamental steps in IT management and IT security understands what physical and virtual IT
These are most likely to be experienced in Middle East and Africa in almost the same magnitudes/levels of severity. Public disorder and domestic extremism are most likely to affect companies operating in Middle East as compared to the ones operating in Africa How the threats presented affect operations such as shipping, personnel security, and business continuity. The threats presented above are most likely to presented affect operations such as shipping, personnel security,
Noncurrent Assets Current assets One may define assets as those properties that are under the ownership or are the possession of a firm. Assets are divided into two like current assets and long-term assets. Long-term assets include land, buildings, and firm vehicles. Current assets are those assets that the firm can easily change their form of cash and they are perceived to take less than one year. Such assets include cash,
.." (Chenoweth and Clarke, 2006) These performance regimes are required to take part in three challenges stated to be the challenges associated with: 1) Overcoming asymmetrical incentives and enlist diverse stakeholders around a collective local security goal despite varying perceptions of its immediacy; 2) Persuading participants to sustain their involvement in the face of competing demands, and 3) Overcoming collective action problems to create a durable coalition around performance goals necessary to
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now