Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Three Critical Elements to Safeguard Enterprise Data

In the wake of recent enterprise-data security breaches, the Information Technology Association of America (ITAA) has issued a list of 10 practical security steps to avoid future information losses. The 10 steps are part of the critical security triangle of process, people, and technology that ITAA says enterprise data professionals should focus on to establish a benchmark for safeguarding their organizations’ most valuable assets. The 10 steps* within the three critical areas for safeguarding enterprise data are:

Process

  1. Routinely assess the risk and vulnerability of physical and electronic enterprise systems and align them with security, incident-response, and business-continuity policies
  2. Document internal controls and audit policy
  3. Integrate security requirements into budgeting and procurement

People

  1. Name a chief information security officer reporting directly to a chief privacy officer and the CEO
  2. Establish, provide training for, and enforce procedures for employees that work remotely (per documented policies for wireline and wireless teleworking)

Technology

  1. Deploy and enforce strong authentication technology and procedures as well as have a clear ID management policy
  2. Implement intrusion detection and intrusion prevention technology to spot and stop hackers from entering your network
  3. Use encryption or other technology to protect data from unauthorized access
  4. Deploy strong remote access security, including virtual private networks with SSL or IPSec and anti-spyware

*Source: Practical Steps for Enterprise Information Security, Information Technology Association of America, May 2006 [PDF]