In previous articles, Castellan Information Security (Castellan) has discussed how it is important that your organization's information security program can't simply be handed over to your IT staff or IT service provider and then assumed that your risks have been sufficiently mitigated. It is also critical to understand that just because your data is stored in the cloud you have not done enough to truly protect your organization's information.
Comprehensive enterprise-wide approaches to information security must go beyond simply deploying a few IT counter measures as the only strategy to address these real threats.
One area that is linked to your information security maturity that is often be overlooked is how your physical security plans align with your data protection needs. To help you better understand this convergence of information security and physical security, Castellan is presenting the following considerations as a starting point:
Assessing where you store sensitive organizational information within your building, office space or elsewhere is a critical place to start. This applies to both digital information and to non-digital data.
It is imperative for organizations to invest in sufficient storage equipment, appropriate infrastructure, and implement internal processes to properly secure information assets. In most cases the investments required are not extensive:
While it is common for organizations to have CCTV systems in place, some systems have not been implemented with the needs of their information security requirements specifically in mind to prevent and properly respond to a data breach. For example, it is important to ensure your CCTV camera system is in place to also monitor higher sensitive information locations such as server rooms, file storage rooms, HR offices, and safes.
Controlling access into and out of offices, buildings and specific workspaces of both internal employees and external guests is a critical starting point for an organization's overall security program. The same is true when considering how physical security measures can help develop an integrated approach to information security.
Organizations should ensure that current and future information security requirements are considered when conducting physical or corporate security planning and reporting functions. For example, infrastructure design, construction, planning, and budgets must take into account information security threats, vulnerabilities and requirements to ensure digital and non-digital information is properly protected.
Castellan Information Security is a Winnipeg-based 'end-to-end' information security company that specializes in information security and have worked with both large and smaller private and public organizations to help them reach their information security objectives. If you have questions about this article or would like to speak to us about how our services can help your company protect its information please feel free to contact us directly at info@castellaninformationsecurity.com.