ARCHIVE
ID Number: LE-15-1852



This research is provided for historical perspective;
portions of this document may not reflect current conditions.






Improving Enterprise Security: From Parts, the Whole
1 February 2002
 
Vic Wheatman  

Strive for due care, due diligence and commercially reasonable security when implementing enterprise security initiatives.









Browse Topics


Other Options







Contact Gartner






Download Document:

PDF

104228.pdf (23.6KB)

Help with Downloads



Improving Enterprise Security: From Parts, the Whole

Strive for due care, due diligence and commercially reasonable security when implementing enterprise security initiatives.


Security is now front and center because of world events and also because of continual waves of new technologies and vulnerabilities. This turmoil means that security initiatives must be ongoing and never finished. Enterprises should strive for "due care," "due diligence" and "commercially reasonable security." However, there are no specific definitions for these terms. Also, in some cases, "good enough" is not good enough; in others, it's perfectly fine.

This issue of the Security and Privacy Spotlight shows how enterprises can improve their security, regardless of the status of their security programs (see "Improving Enterprise Security," AV-15-1568). Enterprises must also do what is appropriate, which seems a little vague, especially because most enterprises want specifics. Generality is necessary, however, in the case of security, because boundaries are unclear — risk profiles, threats, vulnerabilities and cultures are different for each industry, enterprise and geography.

Although a holistic view is necessary, it's also important to focus on the parts of the whole; the end result will be an improved security program overall. Therefore, we offer specific advice on elements that can be made stronger in the security triad of people, process and technology.

Your inquiries and comments are welcome.

Victor S. Wheatman

Editor in Chief

Security and Privacy

spotlight.feedback@gartner.com





Browse Topics:
 





© 2002 Gartner, Inc. and/or its Affiliates. All Rights Reserved. Reproduction and distribution of this publication in any form without prior written permission is forbidden. The information contained herein has been obtained from sources believed to be reliable. Gartner disclaims all warranties as to the accuracy, completeness or adequacy of such information. Although Gartner's research may discuss legal issues related to the information technology business, Gartner does not provide legal advice or services and its research should not be construed or used as such. Gartner shall have no liability for errors, omissions or inadequacies in the information contained herein or for interpretations thereof. The opinions expressed herein are subject to change without notice.




Resource Id: 352380