• Subscribe   
  • Subscribe   

Moving beyond manual policy implementation...

That Security Policy Made My Life Easier & The Process Faster OR Maybe Not Online

When someone asks you if your company prioritizes security, most of us do a quick mental checklist:

  • ✓ Policies
  • ✓ Procedures & processes
  • ✓ Security systems

And answer YES. But, just having these items does not make a company secure, nor guarantee that these security measures are being carried out.

source: slideplayer.com

You should all be familiar with the “Security Pyramid”

In a big organization that is a LOT of documents!

We expect people to recall the security procedure at the point where they are fighting fires and in a panic. This is when the procedure document gets added to the fire instead!

Manual Policy Implementation Cycle

In reality, if it is not effective, people are simply just going to bypass it

So how do you move beyond manual policy implementation?

Introducing Security DevOps…

SecDevOps allows you to automate items so you can break free from manual policy implementation.  There are various levels of automation.

Let’s take a scenario where “James” has resigned and there are a set of associated policies and procedures around staff leaving.

  1. Triggers – When a staff member leaves, everyone with an associated task is notified. They then have to carry out their tasks manually, but there is a defined checklist for each time period (before, during and after leaving) so no one has to guess what is required of them.
  2. Optimize – The manual tasks get optimized. For example, instead of having to remove “James” from 10 systems we have one central system that disconnects him from all systems.
  3. Hybrid – Some optimized tasks and some automated items. For example, a combination of triggers, optimized tasks and some automated items.
  4. Full automation – The ultimate one click solution – one click to disable “James” and SecDevOps takes care of the rest and even provide a validation report at the end.

This may seem like a daunting task, but start somewhere and tackle your biggest pain points first! Then by adding a new feature each month, you’ll quickly be on the path to full automation and happier staff.

Let’s make security policies and processes faster and more efficient, rather than a hurdle people are struggling to get around!

Did you enjoy the read? Then be sure to subscribe to our blog to receive more great posts from our expert bloggers.

By submitting your details via this form, you are consenting that we receive and store your information for the exclusive purpose of sending you email communications.
  • We will not share or publish your information or process it for any other reason.
  • You may stop your email subscription at any time by using the unsubscribe link provided in the footer of our email communications. Thereafter, we will store your details as a record of the beginning and end of your subscription.
  • Please find additional information in our Privacy policy.
View our Terms of use | Protected by reCAPTCHA.

Linda Misauer

Linda Misauer

Head of Global Solutions at Striata

Linda Misauer is the Head of Global Solutions at Striata and is responsible for technical Research and Development, Operations and Project Management for global initiatives.

Linda previously led the Product Management of the Striata Application Platform before moving across to Striata North America as Chief Technical Officer (CTO). As Product Manager, her responsibilities included internal project management of the product development team, market research & product feature design, as well as the product lifecycle management and quality control. As CTO, Linda was responsible for all technical operations for North, Central and South America, including the Project Management, Support, Production and Data Engineering.

Linda has over 10 years of experience in the IT industry, ranging from video streaming solutions and website application development to electronic billing and messaging. Prior to joining Striata in 2002, Linda held the positions of Chief Information Officer at AfriCam, and was IT project manager at Dimension Data.

Linda studied at the University of Natal - Pietermaritzburg and holds a degree in BSc, Majoring in Computer Science and Economics. Linda also has a Diploma in Project Management.

Read more of Linda's blog posts here or connect with her on the following social channels: