Home > Security Tips > Compliance Counselor > Action-forcing mechanisms encourage policy compliance
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Action-forcing mechanisms encourage policy compliance


Charles Cresson Wood, CISSP
04.14.2004
Rating: -2.91- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


One of the most important foundations for a successful information security effort is a supportive motivational system. If motivational systems encourage compliance with information security requirements like policies, then an information security effort is likely to be supported by widespread compliance with requirements. If motivational systems discourage compliance with requirements, then there's no chance that any sort of meaningful compliance is going to be achieved. This Policy Tip discusses one useful type of motivation system called an action-forcing mechanism.

Consider, for example, the case of a hypothetical salesman at a software vendor. The salesman is getting nervous because the end of the quarter is coming up, and he is far from meeting his quota. If he misses his quota he might be fired. The salesman has one particularly large and somewhat promising potential sale that could put him over his quota. He wonders what he could do to motivate this prospect to buy now rather than later, and then hits on the idea of disclosing the plans for an upcoming version of the software. Sure enough, the prospect is impressed, and the sale goes through. There is no consequence for disclosing confidential information to an outside party without a confidentiality agreement. The operational motivational system is the quota, and it encourages the salesman to disregard an information security policy.


MORE INFORMATION ON SECURITY POLICIES:
  • Learn how some companies are using employee dismissal to set an example for policy infractions in this article, Pink slips motivate policy compliance.
  • Read about the importance of having one internal source for all information security policies in this tip also written by Charles Cresson Wood.
  • Listen to this on-demand webcast with speaker Charles Cresson Wood on essential strategies for policy development.

Most organizations have multiple long-standing motivational systems that discourage people from following information security requirements. One example involves a bonus paid to middle managers for restricting departmental spending. If this type of a motivational system exists to the extent that meeting information security requirements involves additional spending at the departmental level, information security is likely to be ignored. Certainly, information security will always involve tradeoffs between competing objectives like cost, ease-of-use and time-to-market with a new product. But without strong motivational systems that support compliance with information security requirements, competing objectives and their motivational systems will most likely overwhelm what little management support there is for information security.

One example of an action-forcing mechanism that encourages information security compliance is the required sign-off from the information security manager for all software systems developed in-house. If the controls on a new or significantly modified application do not meet the information security manager's minimum control criteria, he can withhold his signature. Without his signature, a new application cannot be moved into production. Developers are likely to take security more seriously knowing there is a possibility that this signature will be withheld.

There are many other examples of action-forcing mechanisms -- ways that we can establish motivational systems to encourage and even push workers to comply with information security requirements. Ideally, these action-forcing mechanisms should be approved at the time that the related requirements are established. Management needs to understand that without such action-forcing mechanisms, policies and other requirements documents will simply be ignored.

About the author
Charles Cresson Wood, CISSP, CISA, CISM, is an independent information security consultant based in Sausalito, Calif. He specializes in the development of information security documents including policies, standards, procedures and job descriptions. He is also the author of Information Security Policies Made Easy.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Compliance Counselor,   Security Policy & Infrastructure,   Security Management,   Security Awareness Training and Internal Threats,   Information Security Management,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Compliance Counselor
Creating a HIPAA employee training program
Data protection tips for corporate compliance leaders
PCI DSS compliance requirements: Ensuring data integrity
Understanding PCI DSS compliance requirements for log management
Are 'strong authentication' methods strong enough for compliance?
Strategies for using technology to enable automated compliance
Common PCI questions: Web application firewalls or source code review?
PCI management: The case for Web application firewalls
The basics of enterprise GRC project management
PCI DSS: The structure of a standard

Security Policy & Infrastructure
Tier-1 policy overview: Procurement and contracts, records management
Tier-1 policy overview: Corporate communications, work place security
Presentation: Essential strategies for policy development
Developing security policies
Best practices: E-mail security policies
Week 2: Passwords -- Updating, selecting and recording user and administrative passwords
What constitutes acceptable use?
Infosec Know IT All Trivia: Policy management
Terminating a system administrator
Security policies should work from home too!

Security Awareness Training and Internal Threats
Creating a HIPAA employee training program
Successful rogue antivirus hinges on social engineering
External attacks start with unintentional mistakes, survey finds
Security technologies fail to address insider threat management
Data breach avoidance begins with security basics, panel says
Monitoring program data and internal controls for risk management
Software security threats and employee awareness training
Twitter risks, Facebook threats trouble security pros
Social engineering training could disrupt botnet growth
How to write a risk methodology that blends business, security needs

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
dumpster diving  (SearchSecurity.com)
Honeynet Project  (SearchSecurity.com)
insider threat  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
pretexting  (SearchCIO.com)
shoulder surfing  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
social engineering  (SearchSecurity.com)
Total Information Awareness  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts