Tuesday, 23 October 2020
Recently I have been able to see first-hand what it means not to have a good Security System in an IT project. It is well known by all that it is currently very easy (for some) to enter a computer and be able to manipulate information; but it is not only this that should worry a Project Manager, it is necessary to identify the methods, tools and techniques of all possible attacks in order to analyze the risks and be able to establish the strategies to be applied to prevent or repair the damage they may cause.
Since information is an Asset, it is essential that it is safe against any threat and of any kind, and it is important to understand that information, as we know it, can be presented in any format: on paper, electronic or even spoken in a conversation, which is why we must ensure that it is properly protected.

This protection is established by applying a set of controls, and on this, the UNE-ISO / IEC 17799 standard establishes ten control domains that completely cover Information Security Management, namely:
1. Security Policy.2. Organisational aspects for safety.3. Classification and control of assets.4. Safety linked to personnel.5. Physical and environmental security.6. Communications and operations management.7. Access control.8. Development and maintenance of systems.9. Business continuity management.10. Compliance with legislation.
I want to emphasize point 5: Physical and environmental security; not only must we worry about physical access to information (whether to a building, a room or a computer), but we must also review and analyze the environment and the possible risks or threats (human or natural), however unsuspected they may seem! “If there is a risk, it should be controlled.” And it is at this point where I could verify that, not having developed a good information security management system, in English Information Security Management System (IMSM), could have cost the company that suffered it, millionaire losses (these remained in a high number), but finally it was possible to restore the work environment, although a week later, with what it means to have a business (almost) stopped for a week, and a development team stopped and unable to work; Here it is worth mentioning that it was very helpful the backups that each developer had in their possession, and that to a large extent it was what helped them to restore it.

Finally, just to tell you that, although it involves a high cost (replicating servers, dedicated personnel, infrastructures), the issue of Security in IT Projects is something that must be taken with all the seriousness and responsibility that requires it, since it can cost us not only money (which is already enough), but also legal and even health issues can come into play (if what I lived in this project happens to us, I assure you that it can seriously affect you)

