Security education is one of the five major areas within a security program; the other four being information security, personnel security, physical security and automation security. The importance of a security education cannot be overemphasized, because it is this particular area that increases personal security awareness. From a personnel standpoint, security education directly contributes to the success of the other four areas. In the final analysis, regardless of how definitive and complete any set of security procedures might be, it will be people who execute or fail to execute those procedures.
The purpose of a security education program is to establish and maintain security awareness on the part of all personnel. Security awareness or consciousness is a state of mind, implying an understanding of security objectives, principles, and measures. It also denotes a willingness and desire on the part of the individual to assist, by fulfilling his/her security responsibilities, in achieving the objectives of a security program. This is done by helping the individual acquire an understanding of the basic principles of sound security practices and procedures as they pertain to their unit or job.
Saturday, May 9, 2009
Tuesday, April 28, 2009
Creating a compliance training program for end users
Compliance awareness training is a necessity in view of the laws, regulations and related policies and procedures that it is beholdent upon us to include such training as part of our information security awareness and data protection programs.
Over the past few years there has been a massive increase in security-and privacy-oriented compliance regulations, such as the Payment Card Industry Data Security Standard (PCI DSS), Sarbanes-Oxley (SOX), HIPAA and Gramm-Leach-Bliley (GLBA), to name just a few. Several of these mandate that companies implement security awareness as part of their information security programs. As a result, this often-neglected area of infosec has had some new life breathed into it.
Security practitioners love to argue about the effectiveness of employee security awareness training. Opponents claim the proliferation of security incidents is proof that it doesn't work, whereas proponents claim that no system is perfect, but something is better then nothing. Various studies have been published to support both sides, but one thing is certain: Several compliance regulations exist that mandate employee training about the various security and privacy policies.
But what makes for a good security awareness and education program? Most user training misses the point completely and is as useless as its detractor’s say it is. That's because it focuses on what users should and shouldn't do, as opposed to why and how those actions can have serious consequences.
Over the past few years there has been a massive increase in security-and privacy-oriented compliance regulations, such as the Payment Card Industry Data Security Standard (PCI DSS), Sarbanes-Oxley (SOX), HIPAA and Gramm-Leach-Bliley (GLBA), to name just a few. Several of these mandate that companies implement security awareness as part of their information security programs. As a result, this often-neglected area of infosec has had some new life breathed into it.
Security practitioners love to argue about the effectiveness of employee security awareness training. Opponents claim the proliferation of security incidents is proof that it doesn't work, whereas proponents claim that no system is perfect, but something is better then nothing. Various studies have been published to support both sides, but one thing is certain: Several compliance regulations exist that mandate employee training about the various security and privacy policies.
But what makes for a good security awareness and education program? Most user training misses the point completely and is as useless as its detractor’s say it is. That's because it focuses on what users should and shouldn't do, as opposed to why and how those actions can have serious consequences.
Monday, April 6, 2009
Business Drivers for Information Security Awareness
Raising information security awareness is not a one-off exercise. In the same manner, an awareness raising program cannot then be relied on indefinitely in an organization without further action or modification. To ensure that the program continues to correspond with the targets of a financial organization and that information security is incorporated in the organizational culture, awareness must be maintained or raised continuously. It is an ongoing process, a cycle of analysis and change, as we find it in many quality management systems, such as ISO 9001 or ISO/IEC 27001. Taking this change management approach to an awareness initiative is crucial as it helps close the gap between a particular issue and human responses to the need to change, even in the case of cultural change.
The first step is to analyze the actual information security awareness and culture and to identify the main business drivers. If the culture does not fit with the organization’s targets, the culture must be changed. If it fits, it should be reinforced. The necessary controls such as an information security training program or an awareness campaign must be chosen (planning and design) and realized (implementation). The success of the controls taken must then be evaluated and learning specified (measuring success and program improvement).
When planning an information security awareness program there are several factors which should be taken into account. In this section we will look at the most important issues, why they are important and how to deal with them.
The most critical success factor in any project with organization-wide focus is to obtain executive commitment. This is one of the most powerful levers inside any organization since executive support not only provides funding, but also provides an example to all levels of the organization. The board should appoint someone to formally sponsor the program across the organization. Doing so actively demonstrates to all employees that the program is part of the organization’s strategy and also guarantees an alignment at all levels of the business.
The main output of this activity is to understand exactly why the financial organization needs an awareness program. It is important to state the reasons behind a program, so that it can be made more effective. Among the most recent reasons for launching an awareness program for information security we have the related controls imposed by regulations for example as SOX, BASEL II and other country-specific privacy laws.
It can also be a part of the organization’s strategy - several organizations are pursuing certification objectives such as ISO/IEC 27001 for Information Security Management and BS25999 for Business Continuity Management, which ask for a high level of commitment from every employee. Some control frameworks, like CobiT, also emphasize the need for user training and awareness.
The first step is to analyze the actual information security awareness and culture and to identify the main business drivers. If the culture does not fit with the organization’s targets, the culture must be changed. If it fits, it should be reinforced. The necessary controls such as an information security training program or an awareness campaign must be chosen (planning and design) and realized (implementation). The success of the controls taken must then be evaluated and learning specified (measuring success and program improvement).
When planning an information security awareness program there are several factors which should be taken into account. In this section we will look at the most important issues, why they are important and how to deal with them.
The most critical success factor in any project with organization-wide focus is to obtain executive commitment. This is one of the most powerful levers inside any organization since executive support not only provides funding, but also provides an example to all levels of the organization. The board should appoint someone to formally sponsor the program across the organization. Doing so actively demonstrates to all employees that the program is part of the organization’s strategy and also guarantees an alignment at all levels of the business.
The main output of this activity is to understand exactly why the financial organization needs an awareness program. It is important to state the reasons behind a program, so that it can be made more effective. Among the most recent reasons for launching an awareness program for information security we have the related controls imposed by regulations for example as SOX, BASEL II and other country-specific privacy laws.
It can also be a part of the organization’s strategy - several organizations are pursuing certification objectives such as ISO/IEC 27001 for Information Security Management and BS25999 for Business Continuity Management, which ask for a high level of commitment from every employee. Some control frameworks, like CobiT, also emphasize the need for user training and awareness.
Friday, March 13, 2009
Information Security – Where should it start from?
Information Security of any Organization should start from the employees. The employees should know the seriousness of the data they handle and of course the value of it too. Many organizations has a false believe that an ISO (Information Security Officer) and a Security Team will make the organization secure, you can’t expect the Information Security Officer to make your organization 100% secure. ISO is like all other employees, he has limitations. So if you need the organization to be secure, the employees should work together for the common objective of achieving a 100% security (Although 100% security is a myth, at least the organization will be at its best to preserve the CIA of the information it handles).
Monday, March 2, 2009
Security Awareness and Training
Adequate training of all personnel is critical to the effective implementation of information security. Security awareness and training activities should be ongoing to further demonstrate management’s commitment to information security.
Information security policies and procedures are of little use unless they are understood and observed by the personnel who are affected by them. The agency must be proactive in communicating its expectations and requirements to its personnel, as well as in prescribing disciplinary action for non-compliance. ICT is not sufficient to publish policies and assume that personnel are aware of them, will read them and will adhere to them.
The agency must foster the development of a pervasive information security culture and personalize the issue so that all personnel are aware of their own responsibilities.
Personnel should be made aware of the importance of the information processes, the associated threats, vulnerabilities and risks and understand why controls are needed.
Personnel should be appropriately trained to perform their tasks, prior to access to systems and information being granted. Different levels of training may be required to match the requirements of their jobs. Security officers may require specialized security training or education.
Disciplinary measures that may be invoked for deliberate breaches of security should be publicized.
Periodic information security awareness seminars for all personnel should be conducted to advise of industry developments in information security and of new security initiatives within the agency, to present case studies, and to reinforce the need for security and for complying with the policies and procedures.
Information security policies and procedures are of little use unless they are understood and observed by the personnel who are affected by them. The agency must be proactive in communicating its expectations and requirements to its personnel, as well as in prescribing disciplinary action for non-compliance. ICT is not sufficient to publish policies and assume that personnel are aware of them, will read them and will adhere to them.
The agency must foster the development of a pervasive information security culture and personalize the issue so that all personnel are aware of their own responsibilities.
Personnel should be made aware of the importance of the information processes, the associated threats, vulnerabilities and risks and understand why controls are needed.
Personnel should be appropriately trained to perform their tasks, prior to access to systems and information being granted. Different levels of training may be required to match the requirements of their jobs. Security officers may require specialized security training or education.
Disciplinary measures that may be invoked for deliberate breaches of security should be publicized.
Periodic information security awareness seminars for all personnel should be conducted to advise of industry developments in information security and of new security initiatives within the agency, to present case studies, and to reinforce the need for security and for complying with the policies and procedures.
Tuesday, February 10, 2009
Why Are Most Organizations Still at Risk?
Security technology has helped make information much more secure. Organizations have invested in firewalls, antivirus hardware and software, SPAM filters, Smart Cards, and other such technologies. Additionally, most organizations now have sound data protection policies and procedures in place for dealing with sensitive and business critical information. But even though the technology works, and the data protection policies and procedures are in place, the number and severity of information security breaches are only getting worse.
The missing piece of the equation, as always, is people. In one form or another, human error - not technical malfunction or inadequate business policies - is the most significant risk to protecting data. Based on the 2007 study from the IT Policy Compliance Group, human error is responsible for almost 76% of all data loss.
The human element is typically one of the weakest links in the data protection triangle of technology, business policy, and user awareness and training. While there has been great attention given to protecting data from external threats, evidence shows that it’s the authorized – yet unaware and unversed user – that currently poses the greatest risk to data protection. An effective security awareness and training initiative will address one of the highest risks you face in data protection today – the human element.
Why has the human element become one of the biggest risk factors facing data protection today? The answer: the industry has just done a better job of implementing security technology and aggressively pursuing good data protection policies and practices. But we often neglect to remember that it’s humans who have to use technology, implement the policies, and carry out the procedures. It shouldn’t be a surprise that human behavior, one of the hardest issues to deal with, is now at the forefront of risk.
The missing piece of the equation, as always, is people. In one form or another, human error - not technical malfunction or inadequate business policies - is the most significant risk to protecting data. Based on the 2007 study from the IT Policy Compliance Group, human error is responsible for almost 76% of all data loss.
The human element is typically one of the weakest links in the data protection triangle of technology, business policy, and user awareness and training. While there has been great attention given to protecting data from external threats, evidence shows that it’s the authorized – yet unaware and unversed user – that currently poses the greatest risk to data protection. An effective security awareness and training initiative will address one of the highest risks you face in data protection today – the human element.
Why has the human element become one of the biggest risk factors facing data protection today? The answer: the industry has just done a better job of implementing security technology and aggressively pursuing good data protection policies and practices. But we often neglect to remember that it’s humans who have to use technology, implement the policies, and carry out the procedures. It shouldn’t be a surprise that human behavior, one of the hardest issues to deal with, is now at the forefront of risk.
Sunday, February 1, 2009
Information security awareness – a reminder flyer is not enough
We all know about the importance of the human factor in our information security processes. However, there is no common recipe on how to switch on information security awareness in a given company or organization.
Education and training is only part of the solution - Often the non-privileged IT users are referred to as the weakest link in the security chain. Security issues are:
-opening malicious attachments
-getting caught by phishing
-using weak passwords
-transferring confidential data over insecure channels
-saving company data on a medium without backup
-installing unapproved software
-losing mobile devices
The situation can be improved to some extent by repeatedly teaching the users a list of relevant Do's and Don'ts. But for the remaining part we need a better understanding of the psychological aspects.
Trying to understand human nature - While technology is in permanent development and progress, some components of human character have never changed:
-We rely on long-term experience.
-We estimate risks based on our intuition.
-We feel safe if potential enemies are far away.
-We are used to allowing exceptions.
These properties are obviously not in line with today's requirements for an effective risk-based security framework. We have to accept that human beings don't always think and act in a logical and reliable way. Soft factors play a role in the behavior of users as well as IT specialists; sometimes they even affect decisions in the management. So what are the good arguments for a better security understanding?
Business-focused security awareness - Some of the most effective human awareness sensors are money, law and personal responsibility. In our awareness raising activities we should try to focus on these values. The security goal to be communicated is not to reach a high security level or to reduce IT-related risks, but to ensure business success in a legal framework.
Information security culture - An isolated awareness campaign will usually not induce long-lasting changes in the attitude and behavior of the target groups. Security has to become an integrated part of the business processes. In order to establish and maintain a general culture of security, contributions of different roles are needed:
-Senior Management officially recognizes the importance of security.
-Superiors respect the security policy without any V.I.P exceptions.
-The helpdesk supports users with reliable and helpful services.
-IT architects take account of security throughout their projects.
-Developers consider usability aspects e.g. by compiling comprehensive configuration menus, security warnings and help texts.
-Users knowing what they are doing will cause less incidents.
Secure processing of information and data should be made as easy and normal as possible.
Conclusion - Instead of complaining about human error we should try to understand the reasons for insecure behavior. Information security is only given the appropriate attention if the business impact is visible. Rules and guidelines should always be based on the company strategy and supported by the management. Keep in mind that security awareness doesn't develop very quickly, so never give up!
Education and training is only part of the solution - Often the non-privileged IT users are referred to as the weakest link in the security chain. Security issues are:
-opening malicious attachments
-getting caught by phishing
-using weak passwords
-transferring confidential data over insecure channels
-saving company data on a medium without backup
-installing unapproved software
-losing mobile devices
The situation can be improved to some extent by repeatedly teaching the users a list of relevant Do's and Don'ts. But for the remaining part we need a better understanding of the psychological aspects.
Trying to understand human nature - While technology is in permanent development and progress, some components of human character have never changed:
-We rely on long-term experience.
-We estimate risks based on our intuition.
-We feel safe if potential enemies are far away.
-We are used to allowing exceptions.
These properties are obviously not in line with today's requirements for an effective risk-based security framework. We have to accept that human beings don't always think and act in a logical and reliable way. Soft factors play a role in the behavior of users as well as IT specialists; sometimes they even affect decisions in the management. So what are the good arguments for a better security understanding?
Business-focused security awareness - Some of the most effective human awareness sensors are money, law and personal responsibility. In our awareness raising activities we should try to focus on these values. The security goal to be communicated is not to reach a high security level or to reduce IT-related risks, but to ensure business success in a legal framework.
Information security culture - An isolated awareness campaign will usually not induce long-lasting changes in the attitude and behavior of the target groups. Security has to become an integrated part of the business processes. In order to establish and maintain a general culture of security, contributions of different roles are needed:
-Senior Management officially recognizes the importance of security.
-Superiors respect the security policy without any V.I.P exceptions.
-The helpdesk supports users with reliable and helpful services.
-IT architects take account of security throughout their projects.
-Developers consider usability aspects e.g. by compiling comprehensive configuration menus, security warnings and help texts.
-Users knowing what they are doing will cause less incidents.
Secure processing of information and data should be made as easy and normal as possible.
Conclusion - Instead of complaining about human error we should try to understand the reasons for insecure behavior. Information security is only given the appropriate attention if the business impact is visible. Rules and guidelines should always be based on the company strategy and supported by the management. Keep in mind that security awareness doesn't develop very quickly, so never give up!
Subscribe to:
Posts (Atom)