Security's Everyman

Security's Everyman
Showing posts with label documentation. Show all posts
Showing posts with label documentation. Show all posts

Monday, June 16, 2008

Hello, My name is Andy and I attend meetings

Hi, My name is Andy and I attend meetings. It started out to be just causal meetings with the guys on my IT team. We'd talk about things that we were working on and give tips to help solve problems. Then the meetings became organized. We meet weekly and had agendas and formal discussions. After that I started attending project meetings. These were more hardcore with people from different business units and the formality became more important.

I tried to stop. I didn't like attending meetings but I kept getting pulled back in. Of course the longer I attended the meetings became more hard core. Now I was expected to not only attend but to add value and actually be a leader. Before I knew it I even started leading my own meetings and encouraging others to attend. I didn't like what I had become but I couldn't kick the habit. What started out as once or twice a week has now become a 8 to 15 time a week habit. It's affecting my life and productivity at work. Now not only do I attend and am looked to for leadership and guidance but I've taken the next step. Document review.

That's right, I also review documents to ensure that they, and the projects they support, comply with our security policy and to make design recommendations. Now I spend my days writing policy, planning programs and working to ensure compliance. No longer do I configure equipment and troubleshoot network  and security issues. No longer do I spend my days working with technology.

No longer am I a technology geek. No longer am I a hands on engineer. My name is Andy and I'm a Professional Meeting Attender. Someone please help me find my way out.

Friday, June 06, 2008

In praise of documentation

One of the most important things that a company can do is to document their environment. This holds true for all areas of business. You need to know what you have, how it works, what it's worth (not just in dollars but to the operations of the business), how do you operate without it, what dependencies does it have and what depends on it. When you get into talking about technology you have a few more things to take into consideration. What does it take to keep it up and running, how is it configured and secured, what are the specs required to run it, and on and on.

This documentation gives you the needed information to continue operations, or get back up and running quickly if problems, disasters or failures occur. When done properly it can be the difference between continued operations and closing the door and hanging a "Gone Fishing" sign. It can be the difference between having a system back up and running in a matter of hours or days. Good documentation can cut troubleshooting time down to little or nothing.

Documentation also plays other roles. Auditors ask for lots of documentation of what you are doing and how you can prove it. They want proof of what you say and often good documentation is the proof that keeps them happy.

The problem is that documentation is no fun. Not many people enjoy documenting a server configuration or how the network is connected. Most of us in IT would rather build, fix and configure than document how we did it. This presents a problem when it comes time to rebuild a system and you can't remember how an application was configured or how you had an ACL constructed to help protect the financial department from engineering.

It can also become a nightmare when you get notice that an audit is coming up in the next few weeks or months. It's important to not only have your documentation in order but to know what it is that is expected and what you told them last year you would do this year. Spending a few weeks trying to figure out if you have met the requirements from last years audit and trying to gather all the information needed for this years in not much fun. Not to mention it takes valuable time away from other things that needs to be done.

Managing your documentation is an important part of any program. It is as important as any other piece and often more important. It's kind of like an insurance policy that sits in a file cabinet and you wonder why you spent money on it until you need it. Then you realize that it's worth every dime it cost you. Having someone who is good at documenting and can help you manage it will be a valuable asset to an organization. It will save time and money. It will help keep your stress level low and may well be the difference between a minor blip in operations and a complete shut down in operations.

Friday, July 20, 2007

Out of control network

Like most IT people I've always disliked documentation. At least having to be the one to actually do the documentation. I know it's important and that it can save you and others lots of time when push comes to shove. This has hit me in the face hard since starting my new job. The company uses lots of contractors in the IT department and the network has been built and modified over the years by lots of different people. Documentation has been sporadic at best. So therefore knowing what is going on and why can be a challenge. Almost everyday someone on the team gets a "surprise". They either discover something new, different, unexpected, unexplained, or just plain unnecessary. It's almost comical at times, but when you think about it there are potential serious ramifications.

This has made my job quiet a challenge. It's hard to design a security program when the environment isn't well understood by those who have been there for a while and especially when I'm still learning new things about it. The good news is that we have managements blessing and understanding of how things are and how they need to change. We also have a good team assembled to make this work. I'm amazed at the level of knowledge and understanding that they guys I work with have. They are much smarter than most of the guys I've worked with in the past. These guys are passionate about what they do and they don't like doing shoddy work.

All that said the real purpose of this post is to emphasize the importance of documenting and understanding your network. Not only is it good for daily understanding of what you have and how it works it will come in handy in troubleshooting, DR situations, personnel changes and compliance. Many of the regulations that most of us have to comply with require you to have a well documented environment.

Technology will help you in your information security endeavors but it has to be complemented with documentation, policies, procedures and a well designed User Awareness program. Most of us focus on the technology part but if we want to expand our horizons and ensure that our environments are as secure as they can be it is a good idea to get familiar with the other areas.

  • Look over your documentation and update it. This needs to be done at least yearly and especially anytime you introduce a change in the environment.
  • Read your policies. Ask questions if you don't understand something or if you think something is incorrect. Remember, if your policy says you do it you better do it and be able to prove that you do. The Auditors will want to see the checklist, the archived logs, etc.. Don't be afraid to bring up inconsistencies to Management and to make suggestions.
  • Review the procedures and guidelines that are published within your company. Again many regulations require you to have written procedures for how you deploy systems, handle new users and users that leave. They want to know that you know what is going on and again if your procedures say that you do something they will want to see proof that you do it.
  • Sit in on a UA session or ask to see the material that is used. Make suggestions on ways to make it better and more understandable for the average user. Suggest new things that could be done to make the information easier to retain. People learn in different ways and maybe you have an idea on how to present something in a different format. You may even have the talent to make it happen. You could help put together podcast, videos, RSS feeds, email blasts, or whatever sounds good and works.
As I've said before security goes beyond the server room. It requires that the IT and IS groups work together along with Management, HR, Training and even the end users. We have the knowledge and skills to really make a difference beyond the technology side of things. We just have to get out there and make it happen. I don't think you will regret making the effort.

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.