Free Write 3

If I were a policy-maker, I would obligate companies with more than 20 employees to implement the following minimum set requirements:

  1. Company Policy
    1. Email Policy
    2. Network Access/Security Policy
    3. Password Policy
    4. Wireless Policy
    5.  Review and update every six to twelve months.
  2. Awareness
    1. Make security training personal
    2. Consequences for noncompliance
  3. Training
    1. Provide updates to employees with the latest security vulnerabilities and train them on how to recognize and avoid them
    2. Perform phishing tests
  4. Education
    1. Regularly test your employees’ current security knowledge
    2. Provide visual aids about the policy or helpful hints
  5. Technology
    1. Make sure everything is up to date

Depending on my actual position, and what type of company it is, I may or may not impose fines. For something that may be handling a lot of PII, I would, however, if very little of value is being kept on networks, I may not. My reasoning behind that is one must learn the value in protecting things of value. And no one wants their information stolen.

Leave a Reply

Your email address will not be published. Required fields are marked *