After years in IT, working in various areas of software development, application deployment, and infrastructure and security solutions architecture, I think that security is the most important platform investment for any organization. I think you should invest in security before investing in any of the other Platform Vision solution patterns because if your environment is not secure, it is vulnerable to failure at every level. From an enterprise perspective, when you think about security, it covers everything – identity management, protection of intellectual assets, application and network security, and physical security. Security means protection of organizational assets in all ways. And security is implemented with a combination of technology, processes, and training.
Numerous technologies are available for implementing security at various levels. Some of the forms these solutions can take include hardware and software solutions like firewalls, intrusion detection systems, anti-malware solutions, identity management, authentication mechanisms, encryption, gateways, and VPNs. Also, supplemental technologies are available to protect collaboration, integrated communications, business applications, and development of secure applications from the ground up.
One important aspect of implementing security technology is that the implementation should be governed by the use of proper IT policies and procedures with operational controls. Creating IT policies and procedures is the first and most critical component to any security and management program. The benefits of this approach include the following:
· Creating a baseline from which to operate
· Communicating management’s intent
· Describing acceptable uses of various systems, expectations from users
· Providing best Practices to base the solution on
· Establishing a framework for business continuity and disaster recovery
So to establish a roadmap for implementing security in an organization, you need to:
· Create an IT strategy
· Perform a comprehensive risk assessment
· Establish a control framework
· Determine IT policy
· Implement your security solution
· Set up programs for user awareness and training
· Perform regular audits
Implementation of security with proper IT policy and user training is the key element to creating a solid foundation for all other solution patterns. Security is also key to enabling all of the Platform Vision solution patterns: user experience, Business Intelligence (BI), data management, collaboration and ECM, data management, SOA, next-generation Web solutions, and cloud solutions. A good security strategy and implementation allow you to get the most business value for your organization. When all business functions are surrounded by a security layer, the business can focus more on core business functions rather worry about security issues.
But no matter how much you focus on security, maintaining a secure environment is always an ongoing process. I still remember a quote from a security expert: “Security cannot be measured in absolute terms – either you are less secure or more secure; there is no term like ‘most secure.’”