Search:

Home | Bingo | Bingo Information


Sometimes we fail in raising the security level appropriately

By: julieceo

• Because security is only the batch of processes we think of when our analysis focuses on a particular context, security layers have to precisely adapt to the Information System they're designed for.
• Because security lays on the usual compromise between security and usability and deals with what we spend to protect Information versus how much we are willing to lose if this Information is compromised, security layers have to implement scalability schemes so that we do not overspend resources when it is time to adapt to new technologies or threats.

But sometimes we fail at designing, providing or controlling such scalable and contextual layers of security and the behaviors we were used to live with are not appropriate anymore because the failure drastically proves that some of our security layers were not convenient to protect the related Asset's value.

While those failures may result from multiple factors, the inherited criticality they produce on the related system(s) may not be so easy to characterize :
• We may fail at precisely knowing how much we'll have to spend or accept to lose if an incident occurs and our carefully designed security layers fail one after the other like a house of cards.
• We may fail because the crisis management team we prepared and trained especially for such kind of events also fails in front of a polymorphic ongoing threat that changes form and becomes something much more complex than initially thought of.
• We may fail because external third parties, whether they're involved or not with our main activity, fail in providing us with the right help at the right time.. or worse, choose not to help us as they want to avoid any systemic risk of collapse.

So sometimes we fail ... and occasionally we focus on Getting the Basics Right, which would be a new opportunity to raise the security level appropriately.

Article Source: http://gamblingarticlessite.com

Information Security focuses on designing, providing and controlling contextual and scalable layers of security in order to protect and (re)act the proper way when our Information Assets are put at risks by a threat agent.

Please Rate this Article

 

Not yet Rated

Click the XML Icon Above to Receive Bingo Information Articles Via RSS!

Powered by Article Dashboard