What is computer security?
Computer security is your company's defense against economic loss on the Internet. But unlike what many believe, computer security is not just a question of how many firewalls, anti-virus systems and similar solutions you have. No, computer security is a constant evaluation process.
Areas of Security
Security is normally split into three primary areas: Physical security, Operational security and Management.
Your company should be concerned about each of these three areas and computer security covers two of them - operatioal security and management. Computer security is not just a question of setting up an expensive firewall, buying the best anti-virus software or any similar technical security measure. Computer security is just as much about making good policies for backup, communication, storage, access control, employment, termination - even catastrophy reaction, attack reactions and cleanup after an attack. The times when threats came in the form of evil hackers outside the company, are long gone - the person that could potentially ruin your company could just as well be a member of your own staff. It is, therefore, important to make sure the potential damage will always be small.
CIA - The fundamentals of computer security
In the field of computer security one often speaks of the term CIA - Confidentiality, Integrity & Availability.
These three, somewhat simplified, terms are very fitting in describing the overall goals of computer security:
- Confidentiality - Protection and concealment of information, including personal information, company secrets and financial information.
- Integrity - Verification of the correctness of the information, including detection of unauthorized information editing and protection from misinformation.
- Availability - Availability of information and resources, e.g financial information, contracts, product specifications and similar actives that need to be accessible throughout daily work.
Through the CIA principles and a strongly enforced security policy your company can achieve a more effective and worry-free day where computerized crime is a much smaller issue.
What does this mean for my company?
Principles like CIA are good for explaining the theory of computer security, but what does it mean in practice? Well, it basically means that your company, through groups like Aconiac, can get a very thorough walk-through of your security. A walk-through which does not only focus on the technical aspects, but also on the management aspects like precisely defined procedures, employee politics etc.
To be as secure as possible it is necessary not only to change your IT-solutions, but also the way you use them.
Where does Aconiac come into the picture?
We at Aconiac offer a number of services that can help you achive the security level you want, regardless if it is merely simple protection or full adherence to recognized international security standards.
The services that can help you heighten security in general include Security Testing, which focuses on the technical aspects like security issues in web-applications and servers, but can also be extended to involve management aspects like security policies, employee policies, use-policies etc.