1. 程式人生 > >Ask HN: How do you manage a security policy for your small team?

Ask HN: How do you manage a security policy for your small team?

My company is a small team operating in the digital health space that's recently grown to 12 in the past year. Although we don't deal with a ton of PHI, some of our clients ask us some questions that we've been able to work around but are going to start becoming blockers as we scale.

In terms of our cloud, we're HIPAA compliant and our customers haven't questioned that portion. Examples of things we're asked about are:

1. Infosec staff, policies, and certifications? We do have a light policy but are we already at the size where we need dedicated staff + certifications? There's not anyone today holding everyone accountable.

2. Device management. Some of our employees have devices provided by the company and some use their own (engineers who work remote). We get asked often about if there's antivirus installed on all our devices and what we do to ensure the devices are physically safe. Is the only option here moving to issuing everyone devices and managing them centrally? Is there a middle ground?

3. Anything else on the messy startup side. We share an office with another company which complicates all physical security questions. People tend to take their work home with them as well which also causes potential issues.

Those of you who have done this before / are doing it now, I'd appreciate any tips or suggestions on how to deal with this "middle phase" of growth.

Thanks