BC Advantage - 2009 Issue 1
Computer Security: The 9th Law
Subscribe or sign in to view the full article.
Article Overview
This article explains a general security principle for businesses and healthcare-related environments: risk cannot be eliminated, only managed. It reviews themes from a 10-part security series, including user behavior, physical access, passwords, maintenance, employee trust, network complexity, administration, documentation, and organizational buy-in. The piece is aimed at readers trying to understand practical security governance and the consequences of poor data protection, rather than a technical coding audience.
Why This Topic Matters
It helps readers understand the high-level security mindset behind protecting sensitive information, including why policies, training, and operational controls matter for reducing loss, disruption, and legal exposure.
Article Sections
-
Introduction to the 9th law
The article opens by positioning this installment within a broader 10-part security series and introduces the central theme of risk management.
-
Risk management in security
This section discusses the idea that security work is about reducing exposure rather than eliminating every possible risk. It uses broad everyday comparisons to illustrate the point.
-
Review of the previous laws
The article briefly revisits the earlier laws in the series and summarizes the major security topics they covered. These include software trust, physical access, passwords, updates, employee reliability, network complexity, administration, and organizational support.
-
What risk means for your data
This section explains the business impact of data loss at a general level, including operational, civil, and criminal consequences. It also ties the discussion back to healthcare and patient information in broad terms.
-
Closing remarks
The article closes with a recap of the main message and a preview of the final installment in the series.
What You Will Learn
- How the article frames security as a risk-management discipline
- Why reducing exposure is emphasized over trying to eliminate all risk
- Which broad security practices are reviewed from the earlier series installments
- How data loss can affect a business at an organizational and legal level
- Why documentation, employee cooperation, and general administration matter in security planning
Who Should Read This
- Business owners
- Information security readers
- Healthcare office administrators
- IT and network administrators
- Compliance-oriented readers
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com