Tip

Week 6: Your information security education, training and awareness program

When
Quarterly preferred; annually at a minimum.

Why
Education is the foundation where basic skills and knowledge are developed. Applicable laws or concepts should be introduced.

    Requires Free Membership to View

Most importantly, ensure users understand the "why" of security as well as the "how." An odd psychological factor about people and security is that even if people know how to do something, they often won't if they don't understand why. Next, increase the proficiency of your personnel by practicing what was taught initially. Reinforce what was taught. One caveat in driving home security awareness: Remember that incessant harping leads to apathy -- if you constantly preach security, people will tune you out.

Strategy
Assess the security education, training and awareness program for your organization. Are people practicing what you preach? Are you setting an example? The best opportunity for education is during training/orientation for new employees. Take this opportunity to make all the important security points, and emphasize key policies and important procedures. Designate a time when you know most employees are around so you can have a relatively painless one-shot session, and be sure to keep records -- even a simple sign-in sheet will suffice, but a one-page, signed acknowledgement is even better. During the year, nothing drives security awareness home more than using security incidents that occurred in the company. If you don't want to air your dirty laundry, there are plenty of security incidents in the news that could happen to anyone in your organization.

Present the information through different venues to keep it fresh -- some ideas: computer-based training; videotapes; distance learning; electronic/physical bulletin board; start-up messages on local system; e-mail subscriptions; newsletters; security incidents (lessons learned, how to recognize/avoid next time, preventive measures); previous experience and manuals are just some ideas.

More information
Life, the daily newspaper, professional groups like Federal Information Systems Security Educators' Association. Humor helps, too. Visit the WhatIs.com Fast Guide to IT Humor to get security anecdotes that teach lessons no amount of lecturing can, ranging from sarcastic to outright funny.

About the author
Shelley Bard, CISSP, is a senior security network engineer with Verizon Federal Network Systems (FNS). An information security professional for 17 years, Bard has briefed and written information security assessments and technical reports for the White House and Department of Defense, special interest groups, industry and academia. Please e-mail any comments to mailto:securityplanner@infosecuritymag.com

Opinions expressed in this column are those of Shelley Bard and don't necessarily reflect those of Verizon FNS.

Last week: Licensing and seat management

Next week: Training yourself and your IT staff

This was first published in January 2004

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to:

Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.