article Open access

INFORMATION SECURITY POLICIES AND STRATEGIES AND PRACTICES ADOPTED IN IT: THE IMPORTANCE OF CONSULTANCY IN SMALL AND MEDIUM-SIZED COMPANIES

  • International Journal of Advanced Research
Research footprint

At a glance

Citations
0
References
0
Comments
0
Paper overview

Öz

Objective: Companies in the cybersecurity consulting market are expanding their services in periodic training to business stakeholders and enforcement of security policies. The objective of this work is to demonstrate the importance of consulting in information security policies aimed at small and medium-sized companies. Methods: It is characterized as a narrative literature review with a qualitative approach, which does not use explicit and systematic criteria for the search and critical analysis of the selected literature. Results: Tools needed for cybersecurity include endpoint detection and response (EDR), antivirus software, next-generation firewalls, Domain Name System (DNS) protection, email gateway security, intrusion detection and prevention, logging and log monitoring, endpoint protection, authentication and virtual private network (VPN) services, cloud-based security, web application firewalls (WAFs), software-defined wide area networks (SD-WAN), enterprise password management , privileged access management (GAP), vulnerability and threat management, and threat detection. Conclusions: In summary, SMBs seem to implement some of the basic cybersecurity measures only as part of their overall IT implementation. However, it appears that unless cybersecurity controls are included as part of an IT solution, many SMBs do not realize the resulting potential risks to their business.

Record transparency

Publication details

DOI
10.21474/ijar01/15730
OpenAlex
W4311260093
Document type
article
Language
EN
Source
International Journal of Advanced Research
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.