Mediumsized Companies In our country, the computer security that is practiced in companies is weak, we do not have a culture developed within the staffing structure, the majority of companies do not consider a person dedicated to security features, but that mixes its functions with others such as infrastructure, database, even technical support managementforcing to forget security features to cover the day to day. The idea of an OSI (computer security officer), nor in the correct position within the organizational structure of the company is not conceived. A common practice is to save costs by skimping on computer security, when the business grows considerably or suspected fraud and/or leakage of information, just then there is thought in implementations of computer security. With the massification of Internet use, companies are permanently connected, as well as the increase of computers and mobile applications keep users connected with their company, but the dangers are increased considerably, companies must understand that it is not enough to have a firewall (in fact some do not have one), have set once and leave it at that forever even if you change applications and the infrastructure of the company. It is also a reality that in medium-sized and large businesses that have managed to create an area of computer security, they lose their direction, focusing only on the accesses, and limited by not being able to point faults within the information technology area, because they are trying to avoid internal conflicts. The users awareness is an important factor, if not applied computing enterprise security policies, these would not make sense, i.e. that it for having a series of policy if the user when it is missing or is on vacation facilitates your key to his companions in order to not affect productivity, since the majority considered cumbersome procedures for...

