How to Improve Your IT Security Policy: A Six Sigma Approach

How to Improve Your IT Security Policy: A Six Sigma Approach

Written By
Karen Avery
Karen Avery
Apr 30, 2012
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

You have a security policy. But is it effective? For many companies, chances are the answer is no; more likely, it is slowing down service, increasing costs and disrupting day-to-day operations. No wonder that compliance is not what it should be. In truth, having a policy thats not aligned with business needs may be worse than having none at all. The illusion of security is no match for the real thing.

How do you make sure your security policy is assignable, executable, enforceable and measurable—as it must be to be effective? One approach is to apply the Six Sigma methodology used to improve quality to managing IT security. By paying attention to the customer—the people whom a process or product is supposed to benefit—the Six Sigma approach identifies where security falls short, singles out the causes and makes it possible to measure whether youre making progress in solving the problem. (The term Sigma is used to mean deviations from the norm, or defects; Six Sigma means only 3.4 defects per million products or process cycles.)

In this whiteboard, Gary Lynch and Karen Avery of Booz Allen Hamilton show readers how to apply one of the most important Six Sigma tools, the “DMAIC” process (define, measure, analyze, improve, control), to troubleshoot and improve their security policy. The whiteboard uses the example of a fictitious pharmaceutical company that is struggling to enforce its security rules. By applying Six Sigma, CIOs like our “Jane Doe” can not only discover the reasons their security policy isnt working, but also identify whats needed to make it far more effective.

The whiteboard comprises four PDF pages that can be printed out on standard 8.5″ X 11″ paper. Download now.
After printing the pages, arrange the segments to fashion the whiteboard. You can also download a single-page whiteboard, suitable for screen viewing, or printing on poster board.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.