Should we increase the company’s Level of Security?

Security can either make or break a company’s reputation. If taken seriously, the customers will feel at ease in providing confidential data, which means continued business. This also applies to company rules and policies, as only authorized users are granted access to such top secret information. But then if security is taken for granted, it also means a threat to the company. Leaving relevant information unsafe opens the company to possible law suits. This is why a lot of preventive measures were adapted to increase the level of security within the organization. In information technology, ITIL Security Management is the answer.

ITIL Security Management is intended to make sure that the security aspects of services are provided at a certain level that is both agreed by the service provider and the customer. It provides a common and well-understood concept to both parties in such a way that they will have a better understanding of the reasons behind the needed security policies and procedures.

Based on the Code of practice for information security management (ISO/IEC 17799), ITIL Security Management is divided into two parts. First are the security requirements as written in the Service Level Agreement (SLA) and other external requirements that are specified in other contracts or policies. Second is the realization of a basic level of security to guarantee the continuity of the organization and reach a simplified level of Service Level Management for information security.

  • Share/Bookmark

Leave a Comment

Spam Protection by WP-SpamFree

Previous post:

Next post: