Security:
Computer Security is about protecting the five main types
of IT assets (Hardware, Software, Data/Information, People,
and Documentation) from failure of Availability, Confidentiality,
Integrity and Compliance.
As such it requires a multi-faceted approach. Many people assume
security relates to hacker and virus attacks. This is partly
true but the proper approach to security also involves the analysis
of all risks whether they be physical such as fire or hardware
failure or logical such as a program error causing data corruption.
However absolute security is impossible in exactly the same
way absolute personal or the security of our belongings is impossible.
Computer security requires risk analysis, identifying those
risks that need to mitigated and defended against.
Once those risks have been identified appropriate measures
can be put in place to protect against them. They may include:
* Network Backup Systems.
* Redundant Fileservers
either on or offsite.
* Virus protection measures.
* Firewalls.
* Strong logins and passwords.
* Physical security of assets(locked
areas for fileserver etc).
* Power protection devices.
* Ongoing security audits.
One common mistake that is made that protective measures are
put in place prior to identifying the actual risks that are
unique to your situation. Without a risk analysis process it
is entirely possible to spend money on security measures whilst still
leaving other risks unidentified and at risk of exploitation......
further
information.