Application 2 – Annotated Bibliography

profiletchyar
HowtoCreateaSecurityCultureinYourOrganization.pdf

3 2 T h e I n f o r m a t i o n M a n a g e m e n t J o u r n a l • N o v e m b e r / D e c e m b e r 2 0 0 8

HowtoCreatea Security Culture

inYourOrganization A recent study reveals the importance of assessment, incident response procedures,and social engineering testingin improvingsecurityawarenessprograms.

Glenda Rotvold, Ph.D.

3 2 T h e I n f o r m a t i o n M a n a g e m e n t J o u r n a l • S e p t e m b e r / O c t o b e r 2 0 0 8 • © A R M A I n t e r n a t i n a l , w w w . a r m a . o r g

N o v e m b e r / D e c e m b e r 2 0 0 8 • T h e I n f o r m a t i o n M a n a g e m e n t J o u r n a l 3 3

nformation security has become one of the most important and challenging issues facing today’s organizations. With pervasive use of technologyandwidespreadcon- nectedness to the global environ-

ment, organizations increasingly have become exposed to numerous and varied threats. Technical controls can provide sub-

stantial protection against many of these threats, but they alone do not provide a comprehensive solution. As Kevin Mitnick notes in his book, The Art of Deception: Controlling the Human Element of Security, these technologicalmethodsof protectinginformationmaybeeffective in their respectiveways;however,many loss- es are not caused by a lack of technology or faulty technologybutratherbyusersof technology and faultyhumanbehavior. It stands toreasonthenthatpeoplenotonly can be part of the problem,but also they can and should be part of the solution. People must be an integral part of any organization’s information security defense system. Keeping information secure is not

only the responsibility of information technology (IT) security professionals, but also the responsibility of all people within the organization. Therefore, all users should be aware not only of what their roles and responsibilities are in protecting information resources, but alsoof how theycanprotect information and respond to any potential security threat or issue. Security awareness pro- grams address the need to educate all people in an organization so they can help to effectively protect the organiza- tion’s information assets. But just how well areorganizationsdoing implement- ing security awareness programs and training their employees?

Security Awareness Study Thereare severalwell-knownstudies

on the topic, including Ernst & Young’s “Global Information Security Survey” and CSI/FBI Computer Crime and Security Survey, both done annually. Manyof these studieshave targetedchief

At the Core This article

Explainsthe importanceof security awareness toorganizations

Examines theauthor’s studyof security issues inorganizations

Provides securityawareness trainingadvice

informationofficers(CIOs),chief securi- ty officers (CSOs), and other top-level security professionals and executives in organizations both in the United States and across the globe. Akeydifferencebetween these studies

andtheauthor’sstudythat is thesubjectof this article, “Status of Security Awareness in Organizations:An Analysis of Training and Education, Policies, and Social Engineering Testing,” is that rather than targeting CIOs and CSOs, this study tar- gets other individuals involved with man- agement of information in various types andsizesof organizations. The population studied consisted of

business professionals (primarily within theUnitedStates) including,butnot lim- ited to, records,document, and informa- tion managers, MIS professionals, legal administrators, archives, administrators, and educators. The survey, therefore, examines security awareness from a dif- ferent perspective to determine whether

similar results would be achieved. The main question is: Do other levels and types of information management pro- fessionals have the same level of under- standing of security awareness topics, policies, and procedures within their organizations? The purpose of the study was to

investigate the status of security aware- ness training,IT-relatedpolicies,andthe use of social engineering testing in busi- ness organizations. (The Official (ISC)2

Guide to the CISSP Exam defines social engineeringas:“Successfulorunsuccess- fulattempts to influenceaperson(s) into either revealing informationor acting in a manner that would result in unautho- rized access to, unauthorized use of, or unauthorized disclosure of an informa- tion system,a network,or data.”) This broad, comprehensive analysis

helpsprovideananalysisofhowother lev- els and types of users perceive security awarenesswithinorganizations. Thestatisticalanalysiscanhelporgan-

izations identify potential gaps in their security awareness program, improve their organization’s security awareness program, benchmark progress against other organizations, provide insight into components and characteristics of more formalized security awareness programs, and offer insight into the maturity of organizations’ security awareness pro- grams. The ultimate goal is to strengthen

I

StatusofSecurityAwareness inOrganizations In the final analysis, 144 subjects participated in the University of North Dakota research survey conducted by Glenda Rotvold. Participants came from a variety of organizations, including:

•banking(4.2%) •government(22.2%)

•consulting(5.6%) •healthcare(4.2%)

•education(9.2%) • legal (7.7%)

•energyandutilities (13.4%) •manufacturing(8.5%)

• financial services (4.2%) •other (20.4%)

The “other” category was used to group participants that did not specify a state, including those from Canada or other international sites.

A majority of the respondents reported that their job duties or responsibilities involved working with IT/information systems security,policies,or user training (82.6 percent).A majority of respondents also classified their job as a management posi- tion within the organization (57.6 percent).

3 4 T h e I n f o r m a t i o n M a n a g e m e n t J o u r n a l • N o v e m b e r / D e c e m b e r 2 0 0 8

the human defense security link that guards an organization’s information assets.

Rotvold Survey Results Security Awareness Training: The

majority of survey participants (60 per- cent) reported that their organizations conduct security awareness training. Of the 60 percent that offer security aware- ness training, 44.7 percent said training is mandatory, and 72.8 percent said atten- dance is tracked. This statistic compares to 73 percent

of respondents from organizations required to comply with internal control regulations in the 2005 Ernst & Young studyinvolvingexecutivesfrommorethan 50 countries. No significant difference by type of organization, number of employ- ees,orregionwasfoundonwhethertrain- ing was conducted or mandated or on

whether security awareness training on social engineeringwasconducted. When training was conducted, the

majority of respondents reported that all personnel attend. The most commonly usedmethodstodeliver trainingincluded: face-to-face training sessions, e-mail mes- sages, and online training using web- or intranet-basedaccess.Topicscoveredmost often included policies, acceptable use, passwordprotection,workstationsecurity, confidentiality, viruses, remote access, information sensitivity and classification, and bringing in software from home or inappropriate licensing. Training sessions were offered prima-

rily once a year, typically conducted by information systems (IS) or security staff andwereusually flexible enough to incor- porate new issues or needs. Results indi- cated that training was not typically cus- tomized for different organizational

groups.However, customizingorperson- alizing the training to show how it can benefit people in their jobs has been rec- ommendedbymany security experts as a way to increase the effectiveness of the training and help users incorporate what theyhaveheard. Although input was frequently based

on experiences or incidents (53.4 per- cent), there was agreement by manage- mentontopics,andinputwasalsosolicit- ed from end users (41.9 percent). The majority of respondents (72.1 percent) had received security awareness training within the last year.

Policies: Becausematrixsamplingwas used, respondents were assigned random sections to complete after finishing the demographics and training sections. Ninety-one respondents completed the Policiessection.Only3.4percentreported that theirorganizationhadnopolicies.Of

Table 1. Frequency and Percentages for Security Awareness Training Topics by Percent of Participants in Organizations Reporting SecurityAwarenessTrainingOffered

Security AwarenessTrainingTopics # Respondents %

Policies 73 72.3 Acceptableuse 73 72.3 Passwordprotection 72 71.3 Workstationsecurity 64 63.4 Confidentiality 62 61.4 Viruses 61 60.4 Remoteaccess 55 54.5 Informationsensitivityandclassification 52 51.5 Bringinginhomesoftware/licensing 50 49.5 Downloadingsharewaresoftware 47 46.5 Integrityofdata/information 40 39.6 Spyware 39 38.6 Incidentsreporting 39 38.6 Identitytheft 36 35.6 Specializedcompliance(HIPAA,FERPA,etc.) 33 32.7 Riskassessment 29 28.7 Availability/Disaster recovery 26 25.7 Socialengineering 26 25.7 ServicepackorOSupdates 17 16.8

Source: “StatusofSecurityAwareness inOrganizations:AnAnalysisofTrainingandEducation,Policies,andSocialEngineeringTesting”

3 6 T h e I n f o r m a t i o n M a n a g e m e n t J o u r n a l • N o v e m b e r / D e c e m b e r 2 0 0 8

the respondents answering the Policies section,thetypesofpolicieswiththehigh- est-reported percentage of use were acceptable use, e-mail, password, backup and recovery, anti-virus, software installa- tion and licensing, disaster recovery, and physical security of sensitive areas (See Table2). One of the least-used policies was

social engineering. Only 20.5 percent of respondents reported that they have poli- ciesregardingsocialengineering,andonly 14.3percent reported the social engineer- ingpolicies inuse. When asked who participates in the

developmentof informationsecuritypoli- cies, IS staff received the highest percent- age (60.4percent), followedby IS security

personnel (34.1 percent), department managers (24.2percent), IS steeringcom- mittee (17.6 percent), and all employees (6.6 percent). Other individual responses includedrecordsmanagers,internalaudit, legal, data custodians committee, IT, and vicepresidentof documentmanagement. A majority of respondents reported

that policies are easily available, and almost all reported that the security poli- cies were not too restrictive. A high per- centageof respondents(83.3percent)had read one or more security policies within the last year. The majority also reported reading all of the security policies that apply to themselves.

Compliance: Most respondents reported that theywere awareof the con-

sequences for failing tocomplywith their organization’s security policies (81.7 per- cent). Most organizations also required employees to sign off or attest to reading policies (62.5 percent) and attending training(62.7percent). A substantial percentage of respon-

dents reported that therewerepenalties or consequences for security breaches, including social engineering (48.8 per- cent); however, 41.5 percent did not know if there were consequences, and only 9.8 percent reported no conse- quences. As a percent of total respon- dents, only 2.3 percent provided incen- tives and rewards for compliance, 13.8 percent used compliance as a factor in employee evaluation, and 30.8 percent

Table 2.FrequencyandPercentagesforPolicies inUsebyPercentofParticipants inOrganizationsCompletingPolicySectionQuestions

Security Policies in Use # Respondents %

Acceptableuse 81 89.0 E-mail 77 84.6 Passwordprotection 71 78.0 Backupandrecovery 65 71.4 Anti-virus 64 70.3 Software installationandlicensing 61 67.0 Ethics 55 60.4 Physicalsecurity (sensitiveareas) 53 58.2 Disaster recovery 53 58.2 Remoteaccess 52 57.1 Visitorcontrol 52 57.1 Businesscontinuity 45 49.5 Dial-inaccesspolicy 38 41.8 E-mail retention 39 42.9 Informationsensitivity 44 48.4 Incidentreporting 44 48.4 Overall informationsecurityplan 37 40.7 ISsecurityplan/program 30 33.0 Patchmanagement 25 27.5 Riskassessment 24 26.4 Vendoroversight 22 24.2 Handheldpolicy 20 22.0 Extranet 18 19.8 Socialengineering 13 14.3

Source: “StatusofSecurityAwareness inOrganizations:AnAnalysisofTrainingandEducation,Policies,andSocialEngineeringTesting”

N o v e m b e r / D e c e m b e r 2 0 0 8 • T h e I n f o r m a t i o n M a n a g e m e n t J o u r n a l 3 7

reported penalties for non-compliance. The top three personal motivators

reported for compliance were individual motivation, followed by employee responsibility for information security, and importance placed on information security.

Security Awareness and User Percep- tions:Respondentswereaskedtoratetheir levelof agreementordisagreementwith several statements regarding security awareness and its status within their organizations. The scale ranged from “Strongly Disagree = 1” to “Strongly Agree = 5.”No significant difference by type of organization, size of organiza- tion, or region was found on most of the security awareness and perception variables. The study found many positive per-

ceptions and beliefs regarding various aspects of information security. A high percentage of RIM professionals view information security as important and view people as an important security component. Many also would like to receive more information security training from their organization (M = 3.69). [Editor’s note: M = average].

Good security behavior seemed to be neither recognized nor rewarded, yet

many respondents felt they were moti- vated to follow security guidelines either because of individual motivation and employee responsibility or penal- ties for noncompliance. This would seem to indicate that information secu- rity is viewed as part of everyone’s job responsibility, and that rewards should not become a primary motivating fac- tor. Although respondents seem to

know to whom they would report a securitybreach (M=3.78), theydidnot believe that incident response proce- dures were well understood (M = 2.62). Although these RIM professionals

rated theirknowledgeof theprocedures to report a security breach somewhat higher (M=3.40), itwas still somedistance from an “Agree” or “Strongly Agree” rating. A possible reason is that only 48.4 percent have incident reporting policies and only 38.6 percent of those that offer training cover incidentsreporting.Another40per- cent do not have any security awareness training. It is very possible that incidents may

go unreported because users may not understand all the events that could be considered a breach nor clearly under- stand how and when to report a breach.

This can represent a serious concern for organizations, because they cannot take appropriate action until an incident is reported. Survey respondents generally dis-

agreed with statements that said achievement of security awareness goals is measured or assessed (M = 2.66), effectiveness of overall security awareness program is evaluated or measured (M = 2.74), and there was assessment for continuous improve- mentof the securityawarenessor infor- mation security program (M = 2.79). Assessment and evaluation are neces-

sary to determine if progress or improve- ment in security awareness is being achieved, to provide feedback to make adjustments in the program, and to pro- videabaseline fromwhichtoevaluate the program.It isdifficult fororganizationsto improveorevenknowwhethertheirsecu- rity awareness training and programs are effective if they do not measure it. Other areas that potentially could

be improved include updating policies on a regular basis, identifying and communicating the security awareness goals and message, repeating the secu- rity message often, and creating a secu- rity culture.

3 8 T h e I n f o r m a t i o n M a n a g e m e n t J o u r n a l • N o v e m b e r / D e c e m b e r 2 0 0 8

Creating a Security Culture Although much progress has been

made in improving security awareness in organizations, there is still some work to be done to achieve maturity across the board in these programs. Although 60 percent offered security awareness train- ing, there is still a significant 40 percent thatdidnot. Organizations thatdonothavesucha

program need to look seriously at begin- ning a security awareness program to strengthen this aspect of their security defense systemandprotect their informa- tion resources. Technology alone is not a comprehensive solution. Management awareness, commit-

ment,andsupportwerea fewof themore commonreasonsgivenforsecurityaware- ness training not being conducted. Involving top management and getting their support is essential in building a strong security awareness program that employees will take seriously. If manage- ment commitment is increased, and the security awareness goals and message are communicated and communicated often, progress and improvement can be made increatinga security culture. Security awareness training needs a

foundation of policies. Although many types of policies are in use, there must be more development of policies for inci- dents reporting, availability/disaster recovery, and social engineering. These policies are extremely important and should be included within an organiza- tion’s informationsecurityprogram.Once they are developed, it is crucial that employeesreceivetrainingonthesetopics. Assessmentof securityawarenesspro-

grams and training is another area that should be examined and strengthened further in organizations in an effort to increase their use so continual improve- mentandgrowthcanoccur.Improvement andgrowth,inturn,will allowforsecurity awareness to be fully integrated in the organization, assisting in the overall maturing of the information security program. Security awareness goals first need to

beclearlycommunicated,andthesecurity

awareness message repeated often. Assessment is necessary to measure progress in achieving goals and to obtain necessary feedback that can be used to modify and improve the security aware- ness program. Assessment also needs to occurperiodicallysothattheprogramcan additionally accommodate the changes andnewsecurity issuesthatarise insucha dynamicenvironment. Measurement helps determine

whether program and training objectives have been met as well as the amount of progress achieved in raising the security awarenessof users. According to Information Systems

Audit and Control Association’s Security Awareness: Best Practices to Secure Your Enterprise, measurement not only can reveal whether the awareness program is effective,but also can help to identify any knowledgegapsandensurethecontinuity and improvement of the overall security awareness program. Surveys, interviews, exams, and audits are a few of the more common assessment tools that can be used tomeasureprogress. However, social engineering testing is

another example of a successful method that canbeused tomeasure the effective-

ness of an organization’s security aware- ness program. Social engineering attacks against unsuspecting individuals are a type of security threat that can result in significant data loss. Social engineering attacks are increasing. Although these types of attacks can be just as lethal for organizations as other attacks, it is receiv- ing limited attention with organizations. Social engineering policies and training shouldbedevelopedand implemented. In this study, social engineering was

rated as one of the least-offered training topics in security awareness training, and only half of the 60 percent that offered security awareness training offered social engineering training.Only20.5percentof respondents reported social engineering policies, and only 8.1 percent reported social engineering testing.This represents ahigh levelof concern,andefforts should be initiatedtoensurepoliciesandtraining sessionsexiston this area. By implementing some of these

changes,organizationscanincreasecover- ageofcomponentsfoundinmoreformal- ized security awarenessprograms,achieve higher levels of security awareness maturity, and benefit from a stronger security culture.

Glenda Rotvold, Ph.D., is a Langemo Faculty Fellow in the Information Systems & Business Education Department at the University of North Dakota. She can be con- tacted at [email protected].

References

“CSI/FBI 2007 Computer Crime and Security Survey. Available at www.gocsi.com/press/ 20070913.jhtml.

Ernst & Young. “10th Annual Global Information Security Survey.” 2007. Available at www.ey.com/global/assets.nsf/Finland/Global_Information_Security_Survey_2007/$file/ 10th%20Annual%20GISS.pdf.

Hansche, S., Beri, J., & Hare, C. Official (ISC)2® Guide to the CISSP Exam. Boca Raton: AuerbachPublications,2004.

Mitnick,K.,& Simon,W. The Art of Deception: Controlling the Human Element of Security. Indianapolis:WileyPublishing Inc.,2002.

Rotvold,GlendaM.“Statusof SecurityAwareness inBusinessOrganizationsandCollegesof Business:An Analysis of Training and Education,Policies, and Social Engineering Testing.” Ph.D.dissertation,TheUniversityof NorthDakota,2007.

Wulgaert,T.Security Awareness – Best Practices to Serve Your Enterprise.RollingMeadows,IL: InformationSystemsAudit andControlAssociation,2005.