Showing posts with label Weakest Link. Show all posts
Showing posts with label Weakest Link. Show all posts

Tuesday, January 8, 2019

Humans - A Weakest Link to Security

Humans are considered a weakest link in security. Reasons being

  1. Humans are involved throughout the development, deployment, and ongoing administration of any solution
  2. No matter what physical or logical controls are deployed, humans always finds ways to avoid them, circumvent or subvert them, or disable them
To effectively countermeasure this weakest link following things needs to be considered
  1. Security Policies and Procedures for Hiring and Firing. Policies and procedures for various steps like Hiring, Termination. Hiring will require proper policies for Job Description, classification of job, screening and training. While termination or firing requires proper exit interview, NDA (non disclosure agreement), NCA (non competent agreement) etc.
  2. Separation of Duties
  3. Job Rotation

Thursday, December 20, 2018

How to Safeguard from Human Threat

It is a well know fact that humans are considered the weakest link in security. It is, therefore, very important to consider humans when planning on implementing security solutions in an organization. You may have employed physical and/or logical controls to secure your assets but regardless of what you apply humans can find a way to avoid them, disable them, or subvert or circumvent them.

Various security structures that you can implement to protect from human threats are as follows

  • Following secure hiring practices. This practice include detailed job description and using this as a guide for hiring process. Correctly evaluate candidate for the position.
  • Maintaining roles segregation. This practice includes separation of duties, job responsibilities and job rotation.
  • Establishing policies, standards and guidelines. Set standards, provide guideline and formulate policies for every step. From hiring to termination. Like termination procedure could include disabling access, returning company property, an exit interview etc.
  • Implementing risk management. Risk management is a process of reducing risks to an acceptable level. It identifies, evaluates, prevents/reduces risk to the organization.
  • Implementing awareness training, and management planning. Remember that user's behavior must change for your security solutions to work. So, aware them, train them and educate them.