Reply To: OCU C)ISSO A Discussion Lesson 16
A security officer must prepare an organization for many different scenarios. Creating plans in case something goes wrong is vital for an organization, but it is even better to have measures to prevent these scenarios in the first place as well.
One way to prevent disasters is creating backups. Having information and even certain mechanisms backed up can save a company so much. If something happens to the data or system, the backup can be right there to restore what was lost. This will save much more time and money compared to having no backup and having to start again with things.
Another preventive measure for a security officer is to look at places where the system has vulnerabilities. The system is only as secure as its greatest weakness, so addressing a system’s weakness will make it overall more secure from attacks. This prevents attacks from being able to cause as much damage in the first place, saving much time, data, and money.
A third preventative measure are inspections/tests. Even if there is already a security measure in place, it is always good to go back and make sure that everything is working correctly and that the security is being effective.
Finally, training employees is a good way to prevent disasters. If employees are educated on good and bad practices with their resources, some disasters caused by users can be prevented from occurring in the first place. It is also good to put controls so that one user’s controls cannot bring down the system completely.