10 Mistakes in Enterprise Security
James McGovern from the Enterprise Architect blog compiled a list of “Ten Mistakes that CIOs consistently make that weaken enterprise security.” The list is simple and straightforward.
The 10 Mistakes Are:
- Use process as a substitute for competence
- Hope that the problem will go away if you ignore it
- Put network engineers in charge of security
- Outsource too much
- Rely primarily on a firewall and antivirus
- Authorize reactive, short-term fixes so problems re-emerge rapidly
- Undervalue the cost-savings of security
- Fail to deal with operational aspects of security
- Fail to understand the relationship of information security to the business problem
- Put people in roles and give them titles, but don’t actually train them
A lot of the points have to do with a lax security policy - an inability to define and manage IT security, particularly when it comes to people (as much as process & technology).
Christofer Hoff has added a couple more mistakes to this list including: talking about threats, not risk; avoiding security awareness training; investing for compliance not security, and many more.
Tags: enterprise security, it security, business security, security policy, business, security








Leave a Reply