When a new employee is hired, they are given a specific job title that carries with it certain ACL roles. Many of these roles are not used or required, thus allowing for the possibility of inappropriate access to certain information and possible exposure. When these employees change job titles, rarely if ever, are the ACL's updated.
Not only is this a critical information security issue, it is a security awareness issue. With awareness of this and a proactive and supportive C-Suite and above we can reduce this vulnerability to the security of information.
Friday, October 16, 2009
Tuesday, September 29, 2009
Security Awareness Training and Communication
Security Awareness is the tool most used to inform and educate users on policy and accepted practices and procedures that support the university. It is often the most important and, in many ways, the least expensive way to impact the overall security of an organization. An organization's staff is the most cost-effective countermeasure against security compromises and IT security depends on the cooperation of every user.
Security awareness is also the knowledge and attitude members of an organization possess regarding the protection of the physical and, especially, information assets of that organization. Being security aware means you understand that there is the potential for some people to deliberately or accidentally steal, damage, or misuse the data that is stored within the organization's computer systems and throughout its organization. Therefore, it would be prudent to support the assets of the organization's (non-public personal information [NPPI]).
Security awareness is also the knowledge and attitude members of an organization possess regarding the protection of the physical and, especially, information assets of that organization. Being security aware means you understand that there is the potential for some people to deliberately or accidentally steal, damage, or misuse the data that is stored within the organization's computer systems and throughout its organization. Therefore, it would be prudent to support the assets of the organization's (non-public personal information [NPPI]).
Friday, September 11, 2009
The Current Business Climate and Security Awareness
The protection and security of PII and corporate information needs to minimally be maintained in the current business climate. In fact I believe we must be even more vigilant to insure information security does not fall through the cracks. At times like these it is vitally important we maintain information security awareness, training and education programs.
These are tumultuous times, characterized by shot-gun mergers, acquisitions, and corporate restructurings resulting in mass lay-offs. This corporate churn forces companies to change employee access to sensitive corporate data on very short notice, grant access privileges to new employees, adjust access privileges for re-assigned employees, and terminate access for former employees and contractors.
Organizations that are "identity aware" can successfully - and proactively - manage the IT risk associated with changing user access to applications and systems.
These are tumultuous times, characterized by shot-gun mergers, acquisitions, and corporate restructurings resulting in mass lay-offs. This corporate churn forces companies to change employee access to sensitive corporate data on very short notice, grant access privileges to new employees, adjust access privileges for re-assigned employees, and terminate access for former employees and contractors.
Organizations that are "identity aware" can successfully - and proactively - manage the IT risk associated with changing user access to applications and systems.
Wednesday, August 12, 2009
2008 Information Security Breaches Survey
Companies are becoming increasingly aware of the need to have information security policies in place - with seven out of eight large businesses now claiming to have one. However, experts warn that the high priority given to information security by companies does not necessarily translate into improved security awareness among employees. Increasingly, companies are realizing that to tighten up further on information security, they have to change their people's behavior.
These are among the early findings of the 2008 Information Security Breaches Survey (ISBS) carried out by a consortium, led by Pricewaterhouse Coopers. The survey shows that companies are placing greater trust in their staff and they want them to use technology to improve their effectiveness.
At the same time, the survey shows that employees increasingly targeted by social engineering attacks, where outsiders try to obtain confidential information from employees. Businesses are becoming increasingly concerned about what is being said about them on social networking sites as some employees have posted confidential information on these sites.
Key to making sure that staff remain the organization’s greatest asset is to ensure they behave in a security conscious way. Increasingly, companies are focused on setting clear policies, making staff aware of the policies and then monitoring behavior to ensure that it is in line with those policies.
The report also says that there is some correlation between how clearly senior management understands security issues and whether a security policy is in place. Security awareness is not just an issue for a company's staff. Nearly two-thirds of very large companies would welcome more education for the general public about information security risks. Having a security policy alone does not magically improve security awareness among staff.
The overwhelming majority of companies take steps to raise awareness. The priority given by senior management makes a difference in the extent to which security awareness is drilled into all areas of the organization. What companies are realizing is that increasing security awareness is only part of the answer. The critical issue is changing the behavior of their people.
A 'click mentality' has grown up - users do what expedites their activity rather than what they know they ought to. It is a bit like the road speed limit - everyone knows what they ought to do, but only a few actually do it. Only when behavior changes do businesses realize the benefits of a security-aware culture.
Traditionally, where organizations have attempted to improve employee awareness they have used a combination of computer-based training and face-to-face presentations to get security messages across. But these methods are somewhat transient - much more collaborative and longer-lasting programs are needed. Genuine behavior change is essential, and this takes time and effort.
These are among the early findings of the 2008 Information Security Breaches Survey (ISBS) carried out by a consortium, led by Pricewaterhouse Coopers. The survey shows that companies are placing greater trust in their staff and they want them to use technology to improve their effectiveness.
At the same time, the survey shows that employees increasingly targeted by social engineering attacks, where outsiders try to obtain confidential information from employees. Businesses are becoming increasingly concerned about what is being said about them on social networking sites as some employees have posted confidential information on these sites.
Key to making sure that staff remain the organization’s greatest asset is to ensure they behave in a security conscious way. Increasingly, companies are focused on setting clear policies, making staff aware of the policies and then monitoring behavior to ensure that it is in line with those policies.
The report also says that there is some correlation between how clearly senior management understands security issues and whether a security policy is in place. Security awareness is not just an issue for a company's staff. Nearly two-thirds of very large companies would welcome more education for the general public about information security risks. Having a security policy alone does not magically improve security awareness among staff.
The overwhelming majority of companies take steps to raise awareness. The priority given by senior management makes a difference in the extent to which security awareness is drilled into all areas of the organization. What companies are realizing is that increasing security awareness is only part of the answer. The critical issue is changing the behavior of their people.
A 'click mentality' has grown up - users do what expedites their activity rather than what they know they ought to. It is a bit like the road speed limit - everyone knows what they ought to do, but only a few actually do it. Only when behavior changes do businesses realize the benefits of a security-aware culture.
Traditionally, where organizations have attempted to improve employee awareness they have used a combination of computer-based training and face-to-face presentations to get security messages across. But these methods are somewhat transient - much more collaborative and longer-lasting programs are needed. Genuine behavior change is essential, and this takes time and effort.
Tuesday, July 7, 2009
Essentials in creating an information security mindset
Amidst corporate initiatives to improve profitability, cut costs, improve cash flow, and rationalize investments, C-suite executives still need to spend a chunk of management time on corporate governance. An important aspect of this is information security governance, since information security cuts across all organizational processes.
Key to the success for governing information security is proper, organization-wide awareness. One crucial point is that information security is not just IT security. Since all departments in an organization are affected, information security is everyone's concern. Start with the right security organization.
The security leader must have endorsement and support from the highest levels of management, no less than the CEO if possible. The CEO, as the executive sponsor of the CISO or CSO, demonstrates in no uncertain terms that information security initiatives are organization-wide. The security leader should be supported by a team of self-starters coming from all major departments within the organization.
This team acts as the security champions from the various groups and reinforces information security awareness at the department level. The security leader must communicate the right mindset in safeguarding an organization's information assets. They must articulate this message across a broad audience that may or may not be security-savvy.
Employees may view information security as a hindrance to the smooth performance of their daily duties. It is the job of the security leader to make them appreciate the value to the organization and to themselves of protecting information assets, and the consequences should these information assets be compromised.
The security leader should issue new policies or reminders to articulate the importance of compliance. While written messages are important, these are not effective when used alone. The security leader should make themselves available and visible.
They should tour the office premises from time to time to remind employees of information security policies or seek feedback on the company's security initiatives. One organization I know calls this initiative "One Minute for Information Security." From what I have seen, employees are willing to take even several minutes of their time to dialogue with the security leader.
Another useful tool to strengthen security communications is the use of security awareness seminars for all employees. Videos are an excellent tool to drive home the message. Also, flash videos upon network log-on have proven to be effective reminders. Strategic placement of posters carrying visuals on information security are also good communication channels. Employees especially like corporate giveaways such as pens or memo pads that have security-related reminders.
Regardless of the communications medium or the message, it is important to deliver it in bite-size chunks to avoid confusion and information overload.
Compliance is difficult to enforce, especially if security awareness is not yet mature. One way is to enforce security with penalties for non-compliance (i.e., the "stick" approach).
This has its good and bad points. The penalties can serve as a deterrent, but employees will tend to view information security as a series of don'ts with stiff consequences. Consequently, the right mindset may not be formed.
A simple system of rewards through positive enforcement (i.e., "carrot" approach) is certainly another way to enforce compliance. Let's take clear desk as an example. To encourage clear desks, those in charge of enforcing it can tour the office premises unannounced (e.g., during the lunch break), and place a small token or chocolate, plus a note of appreciation, on compliant desks. The owners of these desks will thus be encouraged to maintain clear desks.
Another approach to implement clear desk is to periodically publish pictures of both compliant and non-compliant desks. You may or may not identify the owners of these desks, depending on the culture in your organization. In this way, employees will get motivated to achieve clear desks themselves if they see that their colleagues and even bosses are doing so.
This leads us to the question of which approach is better: carrot or stick. We can use both, since one complements the other. You can start with the carrot at the early stages of security awareness. Once established, you can use the stick. However, for non-compliance that gives rise to unacceptable risks to the organization, we can use the stick at the outset.
Nothing will drive home the point better than having information security reminders and policies apply to all levels in the organization, from rank-and-file all the way to the CEO. If the security leader or any company executive is not complying with any of the policies, they should be prepared to rectify the situation or suffer the consequences, as prescribed by policy. All employees will thus realize that information security policies are applied fairly to everyone, and that the organization is serious about information security.
Information security awareness tends to be at its peak during periods of audit or certification/recertification (in the case of standards-based information security management systems). The security leader and their team should send clear messages that the security initiatives are not for the audit or certification alone, but should be normal practice at all times.
A good test if an organization has the right level of security awareness is the need for only occasional reminders from the security organization and the self-policing mindset that is adopted by everyone. If you pick any employee at random, from the rank-and-file up to the CEO, and ask what their role for information security is, they should be able to articulate right away how information security depends on them. In other words, the goal is to make information security second-nature to everyone.
Key to the success for governing information security is proper, organization-wide awareness. One crucial point is that information security is not just IT security. Since all departments in an organization are affected, information security is everyone's concern. Start with the right security organization.
The security leader must have endorsement and support from the highest levels of management, no less than the CEO if possible. The CEO, as the executive sponsor of the CISO or CSO, demonstrates in no uncertain terms that information security initiatives are organization-wide. The security leader should be supported by a team of self-starters coming from all major departments within the organization.
This team acts as the security champions from the various groups and reinforces information security awareness at the department level. The security leader must communicate the right mindset in safeguarding an organization's information assets. They must articulate this message across a broad audience that may or may not be security-savvy.
Employees may view information security as a hindrance to the smooth performance of their daily duties. It is the job of the security leader to make them appreciate the value to the organization and to themselves of protecting information assets, and the consequences should these information assets be compromised.
The security leader should issue new policies or reminders to articulate the importance of compliance. While written messages are important, these are not effective when used alone. The security leader should make themselves available and visible.
They should tour the office premises from time to time to remind employees of information security policies or seek feedback on the company's security initiatives. One organization I know calls this initiative "One Minute for Information Security." From what I have seen, employees are willing to take even several minutes of their time to dialogue with the security leader.
Another useful tool to strengthen security communications is the use of security awareness seminars for all employees. Videos are an excellent tool to drive home the message. Also, flash videos upon network log-on have proven to be effective reminders. Strategic placement of posters carrying visuals on information security are also good communication channels. Employees especially like corporate giveaways such as pens or memo pads that have security-related reminders.
Regardless of the communications medium or the message, it is important to deliver it in bite-size chunks to avoid confusion and information overload.
Compliance is difficult to enforce, especially if security awareness is not yet mature. One way is to enforce security with penalties for non-compliance (i.e., the "stick" approach).
This has its good and bad points. The penalties can serve as a deterrent, but employees will tend to view information security as a series of don'ts with stiff consequences. Consequently, the right mindset may not be formed.
A simple system of rewards through positive enforcement (i.e., "carrot" approach) is certainly another way to enforce compliance. Let's take clear desk as an example. To encourage clear desks, those in charge of enforcing it can tour the office premises unannounced (e.g., during the lunch break), and place a small token or chocolate, plus a note of appreciation, on compliant desks. The owners of these desks will thus be encouraged to maintain clear desks.
Another approach to implement clear desk is to periodically publish pictures of both compliant and non-compliant desks. You may or may not identify the owners of these desks, depending on the culture in your organization. In this way, employees will get motivated to achieve clear desks themselves if they see that their colleagues and even bosses are doing so.
This leads us to the question of which approach is better: carrot or stick. We can use both, since one complements the other. You can start with the carrot at the early stages of security awareness. Once established, you can use the stick. However, for non-compliance that gives rise to unacceptable risks to the organization, we can use the stick at the outset.
Nothing will drive home the point better than having information security reminders and policies apply to all levels in the organization, from rank-and-file all the way to the CEO. If the security leader or any company executive is not complying with any of the policies, they should be prepared to rectify the situation or suffer the consequences, as prescribed by policy. All employees will thus realize that information security policies are applied fairly to everyone, and that the organization is serious about information security.
Information security awareness tends to be at its peak during periods of audit or certification/recertification (in the case of standards-based information security management systems). The security leader and their team should send clear messages that the security initiatives are not for the audit or certification alone, but should be normal practice at all times.
A good test if an organization has the right level of security awareness is the need for only occasional reminders from the security organization and the self-policing mindset that is adopted by everyone. If you pick any employee at random, from the rank-and-file up to the CEO, and ask what their role for information security is, they should be able to articulate right away how information security depends on them. In other words, the goal is to make information security second-nature to everyone.
Wednesday, June 10, 2009
Establishing an Information Security Culture
In today’s business world information is a valuable commodity and such needs to be protected. It affects all aspects of today’s businesses from top management right down to operational level. In order to avoid loss or damage to this valuable resource, companies need to be serious about protecting their information. This protection is typically implemented in the form of various security controls. However, it is very difficult to know exactly which controls would be required in order to guarantee a certain acceptable minimum level of security. Furthermore, managing these controls to see that they are always up to date and implemented uniformly throughout the organization is a constant headache to organizations.
There exist several internationally accepted standards and codes of practice to assist organizations in the implementation and management of an organizational information security strategy.
These standards and codes of practice provide organizations with guidelines specifying how the problem of managing information security should be approached. One of the key controls identified by all the major IT Security standards published to date is the introduction of a corporate information security awareness program. The purpose of such a program is to educate the users about Information Security or, more specifically, to educate users about the individual roles they play in the effectiveness of one type of control, namely, operational controls.
There exist several internationally accepted standards and codes of practice to assist organizations in the implementation and management of an organizational information security strategy.
These standards and codes of practice provide organizations with guidelines specifying how the problem of managing information security should be approached. One of the key controls identified by all the major IT Security standards published to date is the introduction of a corporate information security awareness program. The purpose of such a program is to educate the users about Information Security or, more specifically, to educate users about the individual roles they play in the effectiveness of one type of control, namely, operational controls.
Tuesday, May 26, 2009
Definitions for Awareness, Training and Education
Information Security Awareness Program
An Awareness program mixes Awareness training sessions with periodic reminders and promotional materials to bring the attention of information resource users to information security issues, and to increase their understanding of vulnerabilities and threats affecting the security of USAP information. An Awareness program is typically geared towards the non-technical user community, or technical users outside an organization’s Information Technology group. The Federal Information Security Management Act of 2002 (FISMA) and OMB Circular A-130 require all users of federal information resources to receive periodic Awareness training as part of an Awareness program.
Information Security Training
Information Security training is typically considered technical training, and it focuses on improving the security skills and competencies of personnel managing, designing, developing, acquiring, and administering information resources. Technical training is intended for information security staff, and for information technology staff in positions with security related responsibilities, such as system administrators or network engineers. Technical training typically includes short courses, seminars, professional development workshops, conferences, and certificate programs. Technical training is provided to staff by the parent organization, to ensure the staff member is able to accomplish their duties.
Information Security Education
Information Security education integrates all of the security skills and competencies of the various functional specialties into a common body of knowledge, adds a multi-disciplinary study of concepts, issues, and principles, and strives to produce information security specialists and professionals capable of vision and pro-active response. Typically, education involves a long-term course of study at the university level, and is provided to staff at the discretion of the parent organization.
An Awareness program mixes Awareness training sessions with periodic reminders and promotional materials to bring the attention of information resource users to information security issues, and to increase their understanding of vulnerabilities and threats affecting the security of USAP information. An Awareness program is typically geared towards the non-technical user community, or technical users outside an organization’s Information Technology group. The Federal Information Security Management Act of 2002 (FISMA) and OMB Circular A-130 require all users of federal information resources to receive periodic Awareness training as part of an Awareness program.
Information Security Training
Information Security training is typically considered technical training, and it focuses on improving the security skills and competencies of personnel managing, designing, developing, acquiring, and administering information resources. Technical training is intended for information security staff, and for information technology staff in positions with security related responsibilities, such as system administrators or network engineers. Technical training typically includes short courses, seminars, professional development workshops, conferences, and certificate programs. Technical training is provided to staff by the parent organization, to ensure the staff member is able to accomplish their duties.
Information Security Education
Information Security education integrates all of the security skills and competencies of the various functional specialties into a common body of knowledge, adds a multi-disciplinary study of concepts, issues, and principles, and strives to produce information security specialists and professionals capable of vision and pro-active response. Typically, education involves a long-term course of study at the university level, and is provided to staff at the discretion of the parent organization.
Subscribe to:
Posts (Atom)