Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, August 9, 2011

An Overview Of Corporate Security Policies

According to a survey of facilities professionals conducted last year 77 percent of companies have formal, written security policies, while 52 percent review and/or modify these policies at least once per year. How these policies are developed and who's creating them, however, can vary based on factors such as the size of the company, its core business, and its corporate culture.

Corporate re-engineering has had a domino effect on security policy. Security is not a revenue-generating function, so it becomes an area that can be cut. Management functions are combined and companies may no longer have a security director or manager. That function might end up with the facilities director. They have experience with fire-and-life safety systems and HVAC, which are largely code-driven, but they may not be experienced in access control, surveillance, and perimeter protection, which are more 'active' systems in that they're used every day.

Thus, depending on the level of in-house expertise, those with a seat at the table when policy is created can come from the facilities department, human resources, legal, information systems, and administration, in addition to industry consultants. A lot of consultants are strong on the engineering, technical side. Others are focused on operations and security management. A lot of firms are combining these to become full-service banks. A lot of customers are interested in knowing what other customers are doing, what new ideas are out there. Industry-wide 40 percent of businesses now use a consultant when developing policy.

Different strokes

There are a number of other variables at work regarding security policy. Policies and procedures are honed by the culture of the organization they are going to be applied to. In smaller, less structured companies, in terms of formal policies, there may be a cultural change needed when having employees badge in and when companies begin asset tracking. For example in small, start-up software engineering companies, people may have been able to come and go into labs as they wanted. When these small firms departmentalize, this cross-company access might be restricted, perhaps causing some uneasy feelings. Moreover, mergers and acquisitions also can form a rocky marriage in terms of security policy, if one entity's procedures are markedly different from the other's.

Not surprisingly, policy review also may differ based on the type of company in question. Larger companies tend to have more review. In organizations where security is with someone who has multiple responsibilities, the policy can become etched in concrete. It could be years before it's reviewed. And when it is, it's in reaction to an incident.

Overall policy is reviewed not often enough. It's treated as a distasteful, time-consuming task, even in companies with separate security departments, where staff time often is eaten up by the day-to-day business of providing security and managing outside vendors. It's a good thing to annually review and take stock of where you are, but even more significant is an "as-needed" security review that occurs every time facilities, conditions, or culture changes within a company.

We differentiate between policy and procedure, and how and to whom they're articulated within a company. Policy manuals are often distributed to department heads and supervisors. With subordinate employees, higher emphasis is placed on procedures through meetings, posters, and written materials. There's a different level of accountability.

Protecting mind and body

Forming corporate security is a collective activity, in large part because of the variety of facilities in question. The company operates manufacturing, laboratory, and office facilities, that can require varying approaches to security. Policy is a joint venture that combines 'hardware,' such as surveillance cameras and badges, and 'software,' such as people's behavior and habits.

The security strategy is structured around two issues: physical security and information security (i.e., the protection of intellectual property). They're equally important. Physical security revolves around employee badging with picture ID and access control systems, badges for visitors, who must be escorted anywhere in the facility, surveillance cameras, patrols, and training sessions on topics such as workplace violence.

Moreover, various departments ranging from administration to human resources, patents, and laboratory facilities, use the company intranet as a communication vehicle to state individual security procedures of importance. There is no cookie-cutter security model, meanwhile, in our increasingly information-oriented workplace, protection of intellectual property has become a huge issue. Employee orientation covers information security, and employees understand this the first week they come to work. Information security can home in on issues that may seem to be minutiae but can compromise competitive position. For instance, we have visitors coming through so we can't have posted proprietary information that's easily discernible. When employees travel, we tell them to be careful with papers, disks, and laptops. With the threat of industrial espionage and the amount of money the company invests in R&D (Research and development) and new products, public discussion of trade secrets is discouraged, particularly on airplanes.



Julian Arhire is a Manager with DtiCorp.com - DtiCorp.com carries more than 35,000 HVAC products, including industrial, commercial and residential parts and equipment from Honeywell, Johnson Contols, Robertshaw, Jandy, Grundfos, Armstrong and more.

Wednesday, July 27, 2011

Benchmarking And Expert System Software Can Help Companies Quantify Their Security Programs

Meet Company X. It has no formal, written security procedures and essentially handles security-related incidents on an ad hoc, case-by-case basis.

Our next contestant is Company Y. This organization has a formal security program in place and has distributed written procedures to all its employees.

Finally, behind Door No. 3, is Company Z. Not only does it have a spelled-out security program, but it measures its results internally and against other companies in a quest to adopt best practices.

What you have above are three companies at various points along the evolutionary scale of facility security. Where does your company fall in this spectrum? Judging from a recent survey of facilities professionals, you probably don't "wing it" like Company X, but you're also not as sophisticated as Company Z. Welcome to the world of Y.

In short, benchmarking can make the case that your group is providing "added value" to the company. The philosophy behind benchmarking is:

• To compare ourselves to competitors, knowing that the CEO values that comparison;


• To calibrate the quality and effectiveness of our processes with the best in the business;

• To spark our own creativity;

• To accelerate change by learning from other people's mistakes.

Security services in the company are splintered into three reporting areas: Worldwide security (legal); information technology security (business); and physical security (building management).

One technique is "secondary research" - a look at public information and the Internet is a great source on different processes. The goal here is to pick and choose the best elements from different sources to build your own model, rather than simply adopting someone else's program lock, stock, and barrel.

After best practices were identified came the fun part: site visits. The key here is to share information on your own processes, as well.

Benchmarking is just one way to measure security effectiveness. Technology, in this case computer software, can be part of the package, as well. The challenges range from the practical - whether the data collected on an employee can be transferred from one employer to the next - to the philosophical-whether the entire process constitutes an invasion of privacy.

Think back, for a moment, to Company Z mentioned above. It's dotting all the "I"s and crossing all the "T"s when it comes to security. Benchmarking is underway but there's just one problem. The employees have only a vague sense of what the security policies are, and compliance is half-hearted, at best.

Old-fashioned methods for measuring security awareness among employees, such as poster campaigns, audio-visual aids, and clean-desk tests, are not enough. Instead, companies can more accurately measure the security climate within the organization by using a "security thermometer"-a questionnaire for employees that relates to corporate culture and attitudes.

We need to dispense with the negative aura surrounding the term "security awareness." Security awareness is a buzzword we use when things are not going well. It has a negative, excuse kind of meaning-it becomes a garbage bin where we throw our problems. Are employees who don't cooperate with security procedures stupid, lazy, or unwilling? No, their inability to follow security policy probably results from unclear procedures or a lack of buy-in from upper management, which can undermine the policy.

The road to buy-in can be easier if your asset protection approach fits the culture, management style, and business planning of your company, and if the outcomes are measurable. The security thermometer allows security personnel to present quantitative, not just qualitative, data. The thermometer makes manageable the intangible aspects of security awareness of employees and managers.

Here's how it works. The survey is used to gauge perceptions and attitudes, using a five-point scale to rate open-ended questions. The answers can range from strongly disagree to strongly agree. For example, a group of questions might have to do with the protection of documents. Specific survey statements might read as follows: "In my office, I am equipped to take care of secure storage of confidential company documents," or "In my department, the secure storage of confidential documents is discussed at least once every three months."

Calling the thermometer a prevention tool rather than a crime-solving tool, the companies must use only positive statements/questions, not "cop-like, did you do it?"-type questions. As for methodology, it is advised using a questionnaire tailored to one's specific needs, sending it to the employee's home, and then sending a follow-up letter to increase the response rate, which can exceed 50 percent. After the surveys are returned, companies perform the statistical analysis, follow-up with interviews, and write the formal report, which includes improvement steps and an action plan.



Julian Arhire is a Manager with DtiCorp.com - DtiCorp.com carries more than 35,000 HVAC products, including industrial, commercial and residential parts and equipment from Honeywell, Johnson Contols, Robertshaw, Jandy, Grundfos, Armstrong and more.