Skip the navigation

Security Manager's Journal: Taking a Trip to Policy Hell

Be specific in your policies, our manager learns, or users will find ways to skirt the letter of the law.

By Mathias Thurman
July 30, 2007 12:00 PM ET

Computerworld - How often have you heard, Im not sure you can do that; there isnt a policy in place? I hear it too often, because I hate writing policies. And I hate writing policies because at a very engineering-centric company like mine, generic policies dont go over well. If I were to write a policy stating, No running with scissors, I would be asked to define running. How fast can you walk before it counts as running? Does the policy apply to small, blunt scissors?

So, when I write information security policies, theres no such thing as being too specific. I tried to keep our acceptable-use policy fairly generic, not mentioning any specific applications or technologies. Afterward, when I found out that a business unit was using Skype, the manager said, Show me a policy stating that Skype is considered unacceptable use. He argued that his departments use of Skype was saving the company money and increasing productivity, while I countered that Skype is a risky application. His argument held sway until I rewrote the policy to call out specific popular but risky programs.

More recently, I wrote a policy to ensure that all devices on the production network are properly patched. A security assessment had demonstrated the immediate need for such a patch management policy. But the network manager pointed out that in the Cisco world, devices dont get patched  they get a complete IOS revision. She knew exactly what I was referring to, but she wanted the policy to be called the security software update policy.

Her feedback was part of our peer review process. Although peer reviews take more time  because you have to submit them, revise them and resubmit them  I like this approach. For one thing, it helps ensure that policies are enforceable. The network manager might note that a policys wording would require redesigning the entire network, dooming the policy to failure.

Peer review also means no policy comes as a surprise. And the process is respectful of peers. It keeps me from churning out policies that generate resentment. Nonetheless, all that negotiating of terms and content is policy hell for me.

Grabbing Attention

One problem with policies is that once they are published to a Web site, they languish until someone asks, Do we have a policy regarding such and such? That passive approach may be fine for many policies, but others need to be actively promoted. Several months ago, an employee uploaded algorithmic code to his Yahoo briefcase. In the end, we couldnt prove if the employee knew that he wasnt supposed to transfer code to a personal account even if his intention was, as he said, to work from home on the weekend.

This incident shows that we need a way for employees to electronically sign off after reading important acceptable-use or intellectual property protection policies. Such a tool would also be a way to generate general security awareness. Video might be a particularly effective way to make sure our important policy messages stick in peoples minds.

I will start the hunt for vendors that offer policy and security training, and that provide compliance training tools, and Ill report back in a later installment. Until then, its back to policy hell.

This weeks journal is written by a real security manager, Mathias Thurman, whose name and employer have been disguised for obvious reasons. Contact him at mathias_thurman@ yahoo.com.

Read more about Security in Computerworld's Security Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs