Categories
Corporate security of the enterprise
The need to organise the reliable Corporate Security system is faced by any enterprise, regardless of its size, turnover and line of business. Material and information assets, employees, equipment, products, and cash are all potential targets for intruders.
Even if there are no obvious attempts to hack into systems or DDoS attacks at the moment, this does not mean that the company is completely protected. There are many aspects that need to be considered when ensuring Corporate Security of the enterprise. Read more in the material.
A bit of theory.
Information Security (IS) is the preservation of the integrity, confidentiality and availability of information.
Corporate Security (CS) is a set of strategies, plans, policies and technologies used to protect information, physical and information assets, people and processes.
Information assurance (IA) is any data that includes information about the enterprise and its processes, operations, specialists, customers, development strategies, intellectual property, patents, and so on.
Types of threats to enterprise systems
In order to ensure the CS of the enterprise, it is necessary to identify and categorise all potential threats as follows:
-
Physical threats. Relate to physical access to corporate system or its components. They can include theft of funds and products, equipment, as well as unauthorised access to server rooms, sabotage of production processes, intentional or unintentional damage to equipment, etc.
-
Software and hardware threats. These are related to the penetration of potentially dangerous software, such as viruses, Trojans, worms and other programmes that can interfere with or stop enterprise processes. Software and hardware threats are aimed at altering, compromising or deleting data, unauthorised access to enterprise systems for the purposes of extortion, industrial espionage, sabotage, as well as for political, ideological and personal reasons.
-
Threats due to human factors. These are related to the actions of employees of the enterprise. Can be caused by unintentional errors (e.g. accidental deletion of important data) or intentional actions (e.g. embezzlement, corruption, abuse of privileges). It can also include legal threats, such as failure to fulfil obligations to counterparties, tax violations, violations of legislation, i.e. any actions that may lead to administrative and criminal liability.
-
Threats due to human factors. These are related to the actions of employees of the enterprise. Can be caused by unintentional errors (e.g., accidental deletion of important data) or intentional actions (e.g., embezzlement, corruption, abuse of privileges).
In addition, threats to enterprise systems can be categorised into actual and potential threats.
The data collected should be documented and considered when deploying the security system. It is recommended that the list be updated regularly in accordance with changes in the company's operations, as well as when new potential threats are identified.
Threat model and Corporate Security risks of the enterprise
Drawing up a document that describes the threat and risk model helps to plan security measures, assess their effectiveness, and minimise IS risks for the enterprise.
External and internal threats are distinguished.
External threats
External threats are potential hazards that may come from external sources or persons outside the enterprise. They may be aimed at causing damage, stealing money and property, interfering with business processes, or even halting business operations. This includes cybercrime, malware, terrorist attacks, vandalism, and others.
Internal threats
Internal threats to IS come from employees or systems within the enterprise and can be just as dangerous as external threats. They include: negligent handling of IA, abuse of privileges, corruption, sabotage, passing sensitive information to competitors and other intentional or accidental actions against the interests of the enterprise.

Threat model
The KB threat model is formalised description of potential hazards and risks that may cause damage to the company. It identifies critical points in the security system and defines tasks to eliminate them or minimise their possible consequences. The CS includes the following elements:
-
Asset identification: identifying all resources that are of value to the company (information, equipment, technology, etc.).
-
Threat analysis: identification of possible sources of danger to the operation of the enterprise.
-
Threat analysis: identifying possible sources of danger to the operation of the enterprise.Threat probability assessment: determining the likelihood of occurrence based on an analysis of sources, system stability and other factors.
-
Consequence analysis: assessment of possible damage in terms of financial losses, reputational risks and other consequences.
-
Development of protection measures: search for and implementation of means and measures to protect the enterprise.
A threat model may be developed both for individual components of the CS system and for a set of interacting systems and networks.
The creation of such a model allows enterprise management to make informed decisions on planning and budget allocation for the organisation of the security system and to assess the effectiveness of the measures taken.
Corporate Security risks
The CS organisation involves recognising and mitigating risks. Risks can be associated with various aspects of a company's activities and its interaction with the external environment. Some of them are: strategic, reputational, operational, legal and others.
Examples of risks include, among others, the following:
-
sanctions from regulators and lawsuits due to confidential data leakage;
-
disruption of business processes, production stoppage;
-
outflow of customers and partners to competitors;
-
liquidation of the enterprise, etc.
In terms of the degree of possible damage, risks are categorised into:
-
low — with consequences that do not affect the performance of tasks;
-
medium — consequences may cause disruption, financial loss or other negative consequences, but do not threaten the existence of the organisation;
-
high — implementation may result in significant damage to the organisation, such as loss of reputation or breach of legislation.
Risks may also be classified according to the probability of occurrence:
-
unlikely — occur only under certain conditions;
-
likely — possibility of occurrence is assessed as high;
-
very likely — occur frequently or continuously.
Risk classification helps organisations to identify the most important security threats and develop ways of solving protection tasks to prevent or minimise their consequences.
Ways of solving the protection problem in the context of the CS
To ensure the security of corporate data and systems, comprehensive approach must be applied. It includes the following measures:
-
Restrict physical access to: servers, automated control systems (ACS), network devices and other components. This can be done by organising access control systems, video surveillance, access control and other physical security measures.
-
Use of specialised software: antivirus, firewalls, SIEM and DLP systems and other technologies to protect against software malware and unauthorised access.
-
Data encryption: using data encryption algorithms to protect protected information when transmitted over a network or stored on servers.
-
Access control: configuring user rights to access various resources of the corporate system depending on their roles and responsibilities. Assigned rights should be audited once every six months.
-
Authentication and authorisation: the use of passwords, two-factor authentication and other methods to confirm a user's identity before granting them access to the system.
-
Data Backup: create IA backups for quick recovery from failures or disasters.
-
Regular training should be conducted to increase employee awareness of possible IS threats and how to prevent them.
-
It is also important to monitor and analyse security events: regularly analyse event logs for incidents, and monitor user activity to identify suspicious activity and potential threats.
-
Use of SIEM systems: they can be used to monitor security events in real-time mode, analyse large amounts of data from various sources and identify suspicious activity. This allows minimising the risks of IS incidents (cyberattacks, unauthorised access to protected information) and mitigating their consequences.
-
Use of DLP systems: they can be used to control data transfer outside the corporate network, analyse the content of transferred files and block suspicious activities. This helps minimise the risks of financial and reputational damage and other negative consequences associated with the leakage of protected information.
-
As mentioned above, security requires risk analysis to identify the most likely threats and develop appropriate protective measures. Risk analyses should be conducted regularly — at least twice a year — to keep them up to date in accordance with legal requirements or as new threats arise.
-
Finally, you need to ensure regular software updates to address vulnerabilities and improve system defences in timely manner.
The choice of specific measures depends on the specifics of the corporate system, its vulnerabilities, legal requirements and other factors. It is important to regularly review and update your defence strategy in line with changes in technology and security threats.
Regulatory acts and regulatory actions
In the area of enterprise IS, there are a number of international standards that help organisations implement and maintain effective security measures. Here are some of them:
-
ISO/IEC 27001:2022 is an international standard that governs the requirements for establishing, implementing, operating, monitoring, analysing, maintaining and improving an Information Security Management System.
-
NIST SP 800-53 is a guide to Information Security risk management for Federal Information Systems. Provides guidance on implementing security measures, including access control, data protection, vulnerability management, and other aspects.
These regulations and standards define requirements for protection of protected information, personal data, trade secrets, intellectual property and other types of data. They also establish liability for breach of IS rules.
Enterprises are obliged to comply with requirements of regulations and fulfil instructions of regulators. Regulators' actions include monitoring compliance with regulations, conducting inspections and audits, and issuing orders to eliminate violations. Regulators may also initiate legal proceedings in case of serious breaches of legislation.
The next stage in the deployment of the CS system is the identification of objects and subjects of defence.
Objects and subjects of Corporate Security
Identification of the CS objects and subjects allows to determine which company's assets need to be protected.

Organisational measures to ensure Corporate Security
Organising security measures is always about finding a compromise between effectiveness of risk mitigation and non-interference in company's work processes. At the same time, the approach to organising security measures should not be «patchwork» — it is important to take integrated approach: take into account all identified threats and IS risks, and deploy the security system to all divisions of the enterprise.
IS system operation policy
Information is one of the key assets of any business. It includes data about product, customers, suppliers, partners, processes, operations, development strategies, as well as marketing materials and much more. It is one of the most important yet one of the most vulnerable assets. Therefore, it is important to ensure reliable protection of corporate data and systems and to develop a policy for the operation of the IS system.
The IS system operation policy is a document that defines the basic principles and approaches to ensuring information protection at an enterprise.
Among other things, the document contains:
General provisions, which lists the aims and objectives of policy, as well as its scope of application.
Risks and threats. The IS risks and threats identified during the audit phase are listed here.
IS assurance principles. This section lists the main principles that guide a company in ensuring IS.
Other principles include:
-
legality;
-
continuity of protection;
-
feasibility;
-
systematic and comprehensive;
-
avoidance of conflicts of interest between the IS department and other employees of the company;
-
adaptability to the specific needs of each department, etc.
IS security measures. This section describes specific measures that are taken to protect information. These measures include, but are not limited to:
-
access control;
-
use of anti-virus software;
-
continuous monitoring of IS events within the enterprise security perimeter for incidents;
-
data backup;
-
control of all communication channels within the security perimeter, etc.
Allocation of roles and responsibilities. This section defines who is responsible for implementing IS measures in the company. This can be employees of the Information Security department, IT department or other departments.
How to review policy. This section describes how often policy should be reviewed and what changes can be made.
System effectiveness assessment. This describes the requirements for assessing the soundness of the IS system in order to identify vulnerabilities and improve the measures taken.
The IS system operating policy should be adapted to specifics of the company's activities and regularly reviewed to take into account changes in legislation, technology and security threats.
Personal data processing policy
This document describes the purposes and methods of processing users' personal data. The Policy shall be available for familiarisation and posted in any public source.
The document should also describe:
General: aims and objectives of policy and the scope of its application.
Definition of personal data. This section defines the personal data that the business collects and processes. This could be: full name, dates of birth, place of residence, email, phone numbers, browsers used, messengers, etc.
Principles of personal data processing, including lawfulness, fairness and transparency, guarantee of confidentiality, guarantee of using only those data that meet the purposes of processing, etc.
Measures to ensure security of personal data.
Described here:
-
persons responsible for processing personal data of users;
-
used organisational and technical measures for personal data protection;
-
measures taken, etc.
Violation of the latter point may result in reprimands or sanctions from regulators.
The policy is binding on all employees of the company.
Paper handling policy
This is a set of measures and rules that define how paper documents are handled in an organisation. It includes the following information:
-
Classification of documents: division of documents by degree of importance, confidentiality and urgency.
-
Document storage: identifying where to store documents, ensuring their safety and protection from unauthorised access.
-
Document destruction: developing procedure for destroying documents when their retention period expires or they become obsolete. Destruction should be carried out in accordance with legislation on the protection of personal data and commercial secrets.
-
Monitoring compliance with the policy: designating those responsible for compliance with the paper document policy and conducting regular reviews and audits.
-
Employee training: familiarise employees with the paperwork policy and responsibility for breach of the policy.
The paper policy helps minimise the risks of confidential information leaks, protect rights of clients and counterparties, and ensure compliance with regulatory requirements.
List of confidential information
As part of an enterprise security audit, it is necessary to inventory all information assets and categorise them into public, restricted and confidential.
Confidential data includes any information to which access is restricted by law (information relating to trade secrets, intellectual property, know-how, etc.), as well as any data that ensures the competitiveness of the enterprise.
Company's confidential information list may include: customer lists, financial statements, supplier lists, operating manuals, contracts, agreements, contracts, etc.
Procedure for working with removable data carriers
The procedure for handling removable data carriers is documented complex of measures and rules that define the procedure for handling information on removable data carriers at an enterprise.
The document may describe the following requirements:
-
Use only allowed media: the organisation can define a list of allowed media types for use. This can be USB drives, memory cards, optical discs, etc.
-
Media authorisation: an employee must be authorised before using removable media. Authorisation may include verifying the authenticity of the media, whether it matches the list of allowed devices, etc.
-
Protection against unauthorised access: removable media must be protected against unauthorised copying, modification or deletion of information. Encryption, passwords, biometrics and other security methods can be used.
-
Data backup: information must be backed up before it is deleted from the media. Backups should be kept separate from the original.
-
Media registration: all removable media used in the organisation should be registered. Registration may include information about the type of media, owner, date of issue and return, etc.
Compliance with the procedure for handling removable media helps prevent leaks of confidential information, protect the rights of customers and partners, and ensure compliance with legal requirements.
How to get access to the Internet, e-mail
Some enterprises, including critical information infrastructure (CII) facilities, may restrict access to the Internet and email services to employees for IS purposes.
This document should specify set of policies and procedures that define how employees may use these resources for business purposes.
The access procedures may be periodically updated and changed depending on the needs of the enterprise and changes in legislation.
Procedure for determining the degree of user access to data and rules for changing it
Access control is the process of granting or denying permission to access information assets based on predetermined policies and rules.
As part of assigning user access to IA, the following procedures should be performed:
-
Definition of data categories. First of all, it is necessary to define what data will be processed in the system and to which categories it will belong (e.g. confidential, personal data, trade secrets, etc.).
-
Establishing clearance levels. Each category of data has its own access level (e.g., read-only, edit, delete, etc.).
-
Assigning roles to users. System users are assigned to specific roles, each of which has its own set of data access rights (e.g. administrator, operator, user, etc.).
-
Setting up access rights. Based on the user roles and data categories, specific access rights are set up for each user (for example, the right to view certain documents, the right to edit certain fields in documents, etc.).
-
Access control. The system controls how users use the access rights granted to them. Various methods can be used for this purpose, such as auditing user actions, monitoring traffic, etc.
-
Changing the access level. If necessary, the user's access level to data can be changed. This may be initiated by the user, his/her supervisor or the security department. The change of the security clearance must be documented and reflected in the system.
-
Regular review of security clearance. The user's security clearance should be reviewed on a regular basis to reflect changes in the user's job responsibilities, level of trust and other factors.
To control unauthorised transfer of authorisation data between system users or to third parties, it is recommended to use a DLP system.
Software and hardware means of information protection
Software and hardware security features must be used to secure the enterprise's CS.
Such remedies include:
-
Firewalls.
-
Antivirus software.
-
Trusted boot tools. These verify the integrity of the operating system before it is booted and prevent unauthorised access to workstations.
-
Intrusion detection tools. They monitor for suspicious activity on the network and alert security.
-
Cryptographic protection tools. These encrypt data as it is transmitted over the network or stored on servers.
-
Network health monitoring systems. They allow you to quickly identify and fix network problems that could lead to disruptions and reduced security.
-
Vulnerability monitoring systems. This is software or hardware solution that scans the network in real time for vulnerabilities and provides information on how to remediate them.
-
SIEM systems. They analyse security events in real-time and notify the security team of them. This allows you to quickly respond to Information Security incidents.
-
DLP-systems. They prevent data leakage outside the corporate network through the fault of employees.
Using specialised software and hardware allows you to build the reliable protection system, as well as automate the processes of monitoring security events and keep them round the clock, which makes it possible to significantly reduce the workload on personnel.
In conclusion
Ensuring Corporate Security of an enterprise is a complex and multilevel process that requires a comprehensive approach. In order to create an effective security system, it is necessary to take into account all possible threats and risks, as well as to use modern technologies and methods of information protection.
This is the only way to ensure reliable protection of the enterprise from internal and external threats, prevent financial losses, damage to reputation and other negative consequences. Therefore, it is important to pay attention to the CS issues and constantly update protection measures.

















