Information security policy
A security policy is a short written document that says how an organisation protects its information. The top boss approves it so everybody takes it seriously.
- Basic policy: the big goals, such as "keep customer data safe".
- Standards and rules: clear details, such as "passwords must be 12 characters or more".
- Steps (procedures): what to do, for example how to report a lost phone.
A policy must be written in simple words, shared with everyone, and updated when things change.
Risk control: find, score, treat
A risk is a bad event that could happen to something valuable (an asset). To manage it we follow four steps.
- Find the assets (data, computers, people) and the dangers to each.
- Score each risk: risk = chance x harm. Give each a number from 1 (small) to 5 (big) and multiply.
- Treat the big ones first.
- Check again later, because things change.
There are four ways to treat a risk:
- Reduce: make it less likely or less harmful (locks, updates, training).
- Transfer: let someone else carry the cost (insurance, a cloud company).
- Avoid: stop the risky activity (do not store card numbers at all).
- Accept: if the score is tiny, or treating costs more than the harm, just watch it.
What is left after treating is the residual risk.
Business continuity
Even good protection can fail: fire, floods, power cuts, ransomware. Business continuity means the important work keeps going, or restarts fast, when this happens.
- Business continuity plan (BCP): a written plan with who does what, and the order to restart services.
- Backups and a spare site: a second server or copy in another place.
- Recovery time: how long a service can be down. A hospital may allow minutes; a school website may allow a day.
- Practice: run drills so the plan really works.
Fixing the technology after a failure is called disaster recovery. It is one part of business continuity.
The PDCA cycle
Security management never ends. It repeats: Plan (write policy and find risks), Do (put measures in place), Check (test and review), Act (improve). Each turn of the cycle makes the system stronger.
Try it
In the 3D (last step): set the chance to 5 and the harm to 5. Press "Reduce chance" three times. What score do you reach? Now press "Insure". Which button lowers the score more at the start?
At home: list three risks to your phone (dropped, stolen, hacked). Give each a chance and a harm from 1 to 5, multiply, and decide which one to treat first.
Key formulas and definitions
- Risk score = chance x harm (each 1 to 5, so the score is 1 to 25).
- Treatment options: reduce, transfer, avoid, accept.
- Residual risk = the risk left after treatment.
- PDCA: Plan, Do, Check, Act.
- Business continuity = keep going; disaster recovery = repair the technology.
Worked examples
1. A risk has chance 3 and harm 5. Find the score.
Score = 3 x 5 = 15. This is high (red) and should be treated soon.
2. Two risks: A has chance 5, harm 1. B has chance 2, harm 4. Which is bigger?
A = 5 x 1 = 5. B = 2 x 4 = 8. B is bigger, even though A is more likely.
3. A shop buys insurance against a fire in its shop. Which treatment is this?
Transfer. The insurance company carries the money loss.
4. A risk has chance 4, harm 4. Training cuts the chance to 2. What are the old score, new score and the drop?
Old = 16. New = 2 x 4 = 8. The score drops by 8, so it falls from red to amber.
Common mistakes
- Thinking a policy is just a file. If nobody reads or follows it, it is useless.
- Scoring only the chance, or only the harm. You need both.
- Ignoring small risks forever. Re-check them, as things change.
- Believing backups equal continuity. You also need a plan, people and a place to restart.