Creating and enforcing a security policy
Every business needs to have a written security policy that outlines the acceptable practices and expectations for keeping the business secure. These expectations should be clearly communicated to all employees. Small businesses may not have a dedicated IT team or specialist who can create and enforce a security policy. In such cases, the business owner is responsible for enforcing a security policy or security guidelines for the business.
A basic security policy should define how to:
- keep your information, systems and network protected from viruses, spyware and other malicious code
- keep your internet connection secure
- secure your wireless access points and networks
- install and activate firewalls on all of your business systems
- patch your operating systems and applications
- make backup copies of all important business data and information
- control physical access to your computers and network components
- train your employees in basic security principles
- limit employee access to data and information on a needs-only basis
- limit the ability to install software to admin users only