Story 04 · The Foundation
4Putting Security Controls in Place

After a thorough risk assessment, Fawzooz concluded that the next step was to implement security controls tailored to those risks. The controls were divided into several groups covering different aspects of information security management.
Organising information security. Fawzooz set up governance structures and clear roles to ensure clear accountability for information security.
“A good control protects without getting in the way of creativity.”
Human resources security. He organised training so staff understood their security responsibilities, which is crucial in industries with high staff turnover.
Asset management. He identified and classified information assets, from digital content to client data and proprietary tools.
Access control. He restricted access to information and systems to authorised individuals only, which is vital for creative agencies that collaborate with outside parties.
Cryptography. He used encryption to protect the confidentiality and integrity of sensitive data, especially when sent over insecure networks or stored on portable devices.
Physical and environmental security. Protecting physical assets from unauthorised access, damage and interference, including securing the physical sites where creative work is done.
Operations security. Putting suitable procedures in place to ensure information-processing facilities run correctly and securely.
Communications security. Securing information in networks and supporting facilities, which is vital for teams collaborating remotely.
System acquisition, development and maintenance. Making security an integral part of information systems, and information security part of the system life cycle.
Supplier relationships. Managing supplier relationships to protect assets accessed or managed by outside suppliers and service providers.
Information security incident management. Ensuring a consistent, effective approach to managing information security incidents, including communicating about security events and weaknesses.
Information security in business continuity. Building information security into the organisation’s business continuity management.
Compliance. Ensuring the organisation complies with all relevant laws, regulations and contractual obligations.
By implementing these controls, Fawzooz not only strengthened the protection of valuable assets, but also supported and enhanced the creative process. By weaving these practices into daily operations, creative organisations ensured their innovations were secure and their operations compliant, giving them a competitive edge.
Tip: use ← → to move between sections.

