Security Best Practices
Many national and professional organizations have published lists of security best practices. Some of the most helpful guidelines are found in organizational repositories such as the National Institute of Standards and Technology (NIST) Computer Security Resource Center.
Knowing and understanding the value of what you are protecting will help to justify security expenditures.
Create a policy that clearly outlines the organization’s rules, job roles, and responsibilities and expectations for employees.
Restrict access to networking closets and server locations, as well as fire suppression.
Background checks should be completed for all employees.
Back up information regularly and test data recovery from backups.
Regularly update server, client and network device operating systems and programs.
Configure user roles and privilege levels as well as strong user authentication.
Employ an incident response team and test emergency response scenarios.
Choose a security monitoring solution that integrates with other technologies.
Use next generation routers, firewalls and other security appliances.
Use enterprise level antimalware and antivirus software.
Provide training to employees in security procedures.
One of the most widely known and respected organizations for cybersecurity training is the SANS Institute.
Encrypt all sensitive organizational data, including email.