How OPSEC Can Improve Enterprise Security | eWeek

How OPSEC Can Improve Enterprise Security

OPSEC
Jun 7, 2016
2 minute read
eWeek Inhalte und Produktempfehlungen sind redaktionell unabhängig. Wir können Geld verdienen, wenn Sie auf Links zu unseren Partnern klicken. Mehr erfahren


How OPSEC Can Improve Enterprise Security

1 - How OPSEC Can Improve Enterprise Security

Operational security is a way to help organizations of all sizes understand and organize the processes necessary to protect their networks and data.


Overcoming Adversary OPSEC Starts With Detection

2 - Overcoming Adversary OPSEC Starts With Detection

A primary goal of most attackers is to avoid detection while maintaining the availability of their attack infrastructure. For defenders, overcoming adversary OPSEC starts with detection and involves efforts to disrupt, contain and minimize the impact of attacks.


Identification of Critical Information

3 - Identification of Critical Information

For defenders, benefiting from OPSEC starts with a five-step process. The first step is to identify critical information, which provides a baseline for what needs to be defended.


Analysis of Threats

4 - Analysis of Threats

The second step in a defender OPSEC program is to analyze potential threats to understand fully what the threats are and how they could impact the protection of critical information.


Advertisement

Analysis of Vulnerabilities

5 - Analysis of Vulnerabilities

It’s also critically important for organizations to perform a vulnerability analysis that looks at both technology and people within an enterprise as potential vulnerabilities.


Assessment of Risks

6 - Assessment of Risks

After gaining an understanding of what external threats and internal vulnerabilities exist within an organization, the next step is to fully assess all the risks.


Application of Appropriate Countermeasures

7 - Application of Appropriate Countermeasures

With the risk assessment done, enterprises then must apply the right technologies, people and processes to provide operational security that mitigates potential threats and vulnerabilities and protects critical information.


NIST Also Provides Guidance to Follow

8 - NIST Also Provides Guidance to Follow

The Digital Shadows report also suggests that organizations look at the NIST (National Institute of Standards and Technology) recommendations in NIST 800-30, “Guide for Conducting Risks Assessments.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Eigentum von TechnologyAdvice. © 2026 TechnologyAdvice. Alle Rechte vorbehalten

Werbetreibenden-Offenlegung: Einige der auf dieser Website erscheinenden Produkte stammen von Unternehmen, von denen TechnologyAdvice eine Vergütung erhält. Diese Vergütung kann beeinflussen, wie und wo Produkte auf dieser Website erscheinen, einschließlich beispielsweise der Reihenfolge, in der sie erscheinen. TechnologyAdvice schließt nicht alle Unternehmen oder alle auf dem Marktplatz verfügbaren Produkttypen ein.