Home > Ask the Security Channel Experts > Selling Security Technology and Services with Christofer Hoff Questions & Answers > How do I help clients with end-user security policies?
Ask The Security Channel Expert: Questions & Answers
EMAIL THIS

How do I help clients with end-user security policies?

Christofer Hoff EXPERT RESPONSE FROM: Christofer Hoff

Pose a Question
Other Security Channel Categories
Meet all Security Channel Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 29 January 2008
How can a VAR or consultant help clients create and implement end-user security policies?

>
EXPERT RESPONSE

Security policies are living, breathing documents that can profoundly impact the way a company operates. Constructed well, they provide the absolute minimal amount of constraint that achieves the goals of the security organization while still allowing the company to remain agile.

Constructed poorly and without context of the company and its culture, policies for their own sake will ultimately yield a set of unenforceable and inexplicable rules that nobody follows because they simply get in the way.

So the first thing that should be done to help clients create and implement end-user security policies is to understand how security is perceived, instantiated and operationalized within the company. An overall assessment of the company's security strategy should be done to determine the best approach toward creating a framework of policies, procedures and guidelines.

Depending upon the company's tolerance for risk, their culture and regulatory/business requirements, an appropriate set of end-user security policies can be crafted. Aligning them to a security strategy framework means that the policies can be effectively managed across their lifecycle.

It is also very important to set the expectation that policies need to be reviewed and amended at least annually and that these policies should be a business-driven and owned activity, not just a security concern. Encouraging business owners from across the company to participate in the creation and review of these policies is essential if one expects them to be enforced effectively.

Of course, if a customer just wants a set of end-user security policies they can customize and are not interested in a business-aligned security program, there are numerous sets available for purchase or freely downloadable via the Internet.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Selling Security Technology and Services with Christofer Hoff
Can enterprises place too much emphasis on security regulatory compliance?
What are the best data leakage prevention strategies for my clients?
How will the planned changes in PCI-DSS affect the channel?
What is the future of antivirus or antimalware software?
What accounts for the trend toward SMB security?
Where do I start in discussing virtual security with my customers?
Why is it important to use security metrics with my clients?
How can service providers help with IT risk management?
What should I know about green security?
How do I determine the right number of security vendor partners?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts