These elements of computer security are essential to understand and keep in mind when implementing security practices and procedures.
1. Computer security should support the mission of the organization.
The purpose of computer security is to protect an organization's valuable resources, such as information, hardware, and software. Through the selection and application of appropriate safeguards, security helps the organization's mission by protecting its physical and financial resources, reputation, legal position, employees, and other tangible and intangible assets.
2. Computer security is an integral element of sound management.
Information and computer systems are often critical assets that support the mission of an organization. Protecting them can be as critical as protecting other organizational resources, such as money, physical assets, or employees.
3. Computer security should be cost-effective.
The costs and benefits of security should be carefully examined in both monetary and non-monetary terms to ensure that the cost of controls does not exceed expected benefits. Security should be appropriate and proportionate to the value of and degree of reliance on the computer systems and to the severity, probability and extent of potential harm. Requirements for security vary, depending upon the particular computer system. Security benefits do have both direct and indirect costs. Solutions to security problems should not be chosen if they cost more, directly or indirectly, than simply tolerating the problem.
4. Computer security responsibilities and accountability should be made explicit.
The responsibilities and accountability of owners, providers, and users of computer systems and other parties concerned with the security of computer systems should be explicit and defined.
Next>>
a Nigerian world class blogger
Copyright(c) 2009.

No comments:
Post a Comment