Reviewing Information Security Access Control Strategy
Caliber Security Partners
Caliber Security was created to be different; to deliver better solutions and provide long-term support for our clients.
Often in security we get so caught up in firewall rules, anti-virus alerts, or answering audit and compliance surveys that we sometimes put the cart before the horse. We focus on implementing the little details without developing or updating our overall strategy.
Security is, in essence, the art of defining and applying appropriate administrative, technical, and physical controls to provide authorized access and to prevent unauthorized access to resources.
We can streamline our security (and at times reduce our expenses) by reviewing our access control strategy on a regular basis.
Access control is really a matrix of access control groups (administrative, technical, and physical) and access control types (preventive, detective, corrective, recovery, deterrent, and compensating).
Access Control Strategy – Rapid Assessment
As we step back and reconsider access control, it’s important to spend some time ensuring we have good coverage horizontally and vertically throughout the matrix. Some things to look for:
Access Control Reviews
Many security and privacy frameworks require us to review our risks on a regular basis, and ensure we have appropriate countermeasures. As security leaders, we should take a similar approach to access control reviews—assessing our controls based on group and type, to make sure our matrix is balanced and effective. As we roll risks together into mediation projects, we should also be considering our access control matrix gaps and including those in mediation efforts as well.
Need help with reviewing your access control strategy? Caliber Security Partners can help you build and analyze your access control matrix.?Just contact us at?[email protected]??