The security of any system or network is a combination of technology,policy,and people,and it requires a wide range of activities to be effective. A strong security program begins by assessing threats to the organization's computers and network,identifying actions that address the most serious vulnerabilities, and educating users about the risks involved and the actions they must take to prevent a security incident. The IT security group must lead the effort to implement security policies and procedures,along with hardware and software tools to help prevent security breaches.However, no security system is perfect, so systems and procedures must be monitored to detect a possible intrusion.If an intrusion occurs,there must be a clear reaction plan that addresses notification, evidence protection, activity log maintenance, containment, eradication, and recovery.