{
    "success": true,
    "data": {
        "id": 1147791,
        "msgid": "it-security-procedures-are-they-being-implemented-1447893297",
        "date": "2005-03-21 00:00:00",
        "title": "IT security procedures -- are they being implemented?",
        "author": null,
        "source": "TEDY DJAJAWINATA",
        "tags": null,
        "topic": null,
        "summary": "IT security procedures -- are they being implemented? Tedy Djajawinata, Contributor, Jakarta, tedy.djajawinata@csindonesia.co.id Many companies spend long hours and excessive amounts on consultancy fees in developing IT security procedures for different reasons. Some are genuinely keen on protecting valuable information assets, while others are responding to issues raised in audit reports.",
        "content": "<p>IT security procedures -- are they being implemented?<\/p>\n<p>Tedy Djajawinata, Contributor, Jakarta, tedy.djajawinata@csindonesia.co.id<\/p>\n<p>Many companies spend long hours and excessive amounts on<br>\nconsultancy fees in developing IT security procedures for<br>\ndifferent reasons.<\/p>\n<p>Some are genuinely keen on protecting valuable information<br>\nassets, while others are responding to issues raised in audit<br>\nreports.<\/p>\n<p>Regardless of the motivations and the energy spent in<br>\nproducing these procedures, are they actually being properly<br>\nimplemented?<\/p>\n<p>It is not surprising to often hear, \"Not exactly\", as the<br>\nanswer to this question. It is indeed a very challenging job for<br>\nan IT Manager to ensure that these procedures are effectively<br>\nimplemented by his staff.<\/p>\n<p>And, it is a fact, IT staff in turn have numerous excuses for<br>\nnot implementing them. However, some practical insights could<br>\nhelp the IT manager address these issues:<\/p>\n<p>\"We are not aware of any procedures related to what I do\"<\/p>\n<p>Ensure that all procedures are published and disseminated to<br>\nyour staff, and your users when appropriate. If necessary,<br>\ninclude these in their job descriptions. Have the designated<br>\nchampion for each procedure explain it to the rest of your staff.<\/p>\n<p>Everyone should know who does what and how. Use the same<br>\nopportunity to get feedback from your staff on potential issues<br>\nrelating to the implementation of the procedures.<\/p>\n<p>\"I don't really understand the procedures. They are too<br>\ncomplicated\"<\/p>\n<p>Ensure that your procedures are concise and easy to<br>\nunderstand. Use the language understood by your staff. For<br>\nexample, use Bahasa Indonesia if necessary. Also, develop very<br>\npractical, yet effective and well-structured procedures clearly<br>\ndescribing who does what.<\/p>\n<p>Complex and wordy procedures usually discourage people from<br>\nimplementing them. Remember that the main audience for your<br>\nprocedures is your staff, not your auditors.<\/p>\n<p>\"There is no way we can do this here (in this organization)\"<\/p>\n<p>Recognize the objective of each task. If necessary, use a more<br>\npractical alternative method for your organization to achieve the<br>\nsame objective. Ensure that your procedures are well suited to<br>\nyour IT environment.<\/p>\n<p>Simply copying and pasting them straight does not help.<br>\nHowever, bear in mind that some objectives can only be achieved<br>\nby changing the way certain activities are conducted by your<br>\nstaff and users. Additional tools and skills may be required to<br>\nachieve these.<\/p>\n<p>\"Users complained to us about the bureaucracy\"<\/p>\n<p>It is commonly understood that, from the users' point of view,<br>\nit is always easier and faster to get things done without having<br>\nto go through the procedures. In this case, it is important that<br>\nthe validation as well as the necessity for changes are well<br>\ncommunicated to your most senior management and eventually to<br>\nyour users to gain their full support.<\/p>\n<p>\"I don't do this because it's not yet on the procedure\"<\/p>\n<p>Ensure that you keep the procedures up to date and in line<br>\nwith the changes to your environment. These updates must be<br>\nimmediately communicated to affected staff. Ensure that your<br>\nstaff keep only the most current version, and only one version.<\/p>\n<p>\"What's in it for me?\"<\/p>\n<p>It may be a disturbing but nevertheless common question from<br>\nthe IT staff. It may not be easy to establish, but one of the<br>\nmost effective tools to address this is to use consistency in<br>\nexecuting the procedures as one of the Key Performance Indicators<br>\n(KPIs) of your staff.<\/p>\n<p>Remember that their performance is also your KPI.<\/p>\n<p>\"How am I doing?\"<\/p>\n<p>Perform periodic audits on each procedure. If available, also<br>\nask your internal audit team to perform periodic internal audits<br>\non your team. Immediately address any issues raised in and during<br>\nthe audit.<\/p>\n<p>And finally, congratulate your staff on having fewer IT-<br>\nrelated issues raised in your organization's audit report.<\/p>\n<p>The writer is a principal, information system services, at PT<br>\nConsulting Services Indonesia<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/it-security-procedures-are-they-being-implemented-1447893297",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}