Discussion and Replies

profileCyberSter
Information_Security_Fundamentals_----_Chapter_5_Building_and_Maintaining_an_Effective_Security_Awareness_Pro....pdf

93

Chapter 5

Building and Maintaining an Effective Security Awareness Program

John G. O’Leary

Contents Overview ........................................................................................................... 110 Overall Objectives of This Chapter .................................................................... 111

Specific Objectives of This Chapter ............................................................... 111 To-Do’s for Readers ...................................................................................... 111

Chapter Outline ....................................................................................... 111 Terminology ......................................................................................................112 Rationale ........................................................................................................... 115

Why We Need Information Security ............................................................. 115 What Is “Awareness,” Anyway? ...................................................................... 116 Why IT Security Awareness? ......................................................................... 117

Making Awareness Happen ............................................................................... 117 Appoint an Awareness Team ......................................................................... 117 Translate Goals into Action Plans ................................................................. 118 Targeting the Program .................................................................................. 118

Needed Skills .....................................................................................................122 Desired Outcomes .............................................................................................124 Group Culture ..................................................................................................124 Program Content Factors ..................................................................................125

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

94  ◾  Information Security Fundamentals

Overview Technology is a wonderful thing. Security technology keeps improving. It makes our jobs easier and strengthens the security of our computers and communication resources. And some of the newer and more advanced technologies require little or no human intervention. But the bad guys are improving, too; and so is their tech- nology, and it’s doubtful that we’ll ever eliminate the actions or effects of carbon- based life forms (that’s us) in information security.

We’ve all heard of “security awareness” and we’ve all got some picture or notion of what that phrase means. Those initial notions, however, tend to be incomplete. Security awareness includes multiple activities and different approaches aimed at various levels of our organizations and seeking large-scale or subtle behavioral changes in addition to just being aware of particular threats. We must educate managers, users, and IT personnel on the importance of protecting information resources. Top managers need to know in macro the bottom-line terms. IT security professionals need detailed technical training. Computer users, application devel- opers, and technicians must be shown what they can do on a day-to-day opera- tional basis. This chapter tries to deliver practical ideas and techniques on how to tailor a computer security training/orientation program to diverse groups. We will cover how to plan a program. We’ll see who needs to be involved in initiating the program, how to define target audience segments, what possible topics to focus on, and which meeting and presentation techniques are most effective. We’ll also give

Program Content Items .....................................................................................127 Degree of Detail ................................................................................................130 Locating Resources and Information .................................................................131

Internal Sources ............................................................................................131 External Providers .........................................................................................132

Pinpointing Areas of Deficiency ........................................................................133 Delivery Methods and Techniques .....................................................................133

Presentations .................................................................................................134 Formal Security Courses ...............................................................................135 Demos ..........................................................................................................135 Purchased Videos or DVDs ..........................................................................135 Publications ..................................................................................................137 Small Pamphlets and Booklets ......................................................................139 Formal Courses .............................................................................................140

Special Events ....................................................................................................141 Selling the Program ...........................................................................................142 Dealing with Management ................................................................................143 Maintaining Compliance ..................................................................................144 Conclusion ........................................................................................................145

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  95

some tips and techniques for dealing with management, whose support is crucial to the success of the program.

Overall Objectives of This Chapter At the end of this chapter, students should be better able to plan, develop, and implement an effective, realistic, focused, and efficient security awareness program.

Specific Objectives of This Chapter At the end of this chapter, students should be more able to

◾ Evaluate existing security awareness measures for applicability and effective- ness in their environments

◾ Ascertain specific IT security needs for different job functions and environ- ments in their organizations

◾ Locate areas that need improvement to attain required levels of security compliance

◾ Identify realistic training options differentiated by content, costs, availability, vendor, and scheduling that will bring weak areas into compliance and pre- vent solid areas from becoming deficient

◾ Set priorities and implement the training and awareness program ◾ Understand principles and techniques for motivating people to perform the

security-related components of their jobs well ◾ Analyze training content and technique alternatives for different audiences ◾ Determine ways to plan and sell computer security awareness programs

within their organizations ◾ Examine ways of evaluating the effectiveness of their programs ◾ Identify ways of gaining support and compliance from the user community

To-Do’s for Readers Think in terms of relevance to your environment, now and in the future. Remember that “workable” is more important than “elegant.”

Chapter Outline

Terminology Rationale Making Awareness Happen Targeting the Program Needed Skills

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

96  ◾  Information Security Fundamentals

Desired Outcomes Group Culture Program Content

Factors Items Degree of Detail

Locating Resources and Information Internal External

Pinpointing Areas of Deficiency Delivery Methods and Techniques Special Events Selling the Program Dealing with Management Maintaining Compliance

Terminology The following is a partial list of terms relevant to the topic and comments on how to think of them in an “awareness” mode:

Awareness—cognizance. The realization that, in this case, both threats and countermeasures exist and that our organization is not automatically immune or untargeted. This is the “what” and the “why” that drives our need for…

Training—delivering techniques and explaining policies, products, and proce- dures. This is the “how” that ensures people at all levels can understand and perform the actions and use the provided countermeasures.

Education—what we really want to do. Awareness without training gets them all nervous and doesn’t give them answers. Training without awareness doesn’t give them the motivation to learn and learn well. We want to put our security measures and activities in the proper organizational context. An educated workforce is an extremely strong defense mechanism.

Motivation—getting buy-in. Convincing the targets of our awareness program that the measures we propose will really help, and that they should, therefore, actually do what we suggest and bring about some…

Behavioral change—this is the real measure for any security awareness program. In an effective program, the mental gear shifting is followed by changes in the way things are done. There’s a little bit of a subtle difference here because the behavior we want to emphasize might be what they’re already doing. If so, stress the security and operational benefits of staying the course and keeping alert. Behavioral changes we want to effect must be clearly delineated and

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  97

explained in the context of how the people affected by the changes do their jobs.

Outcomes—did the suggested (or demanded) changes actually take place? And did they improve the security of the enterprise? Are they changing passwords more frequently and not using their dog’s names? Have they learned how to operate and do they actually use the self-encrypting hard drives? Are they losing fewer laptops or handheld devices? And so on.

Deliverables—management wants to see concrete results. What are they get- ting for the money and resources they allow us to spend on this exercise? Keeping our outcomes tied to behavioral changes usually makes it easier to demonstrate some quantitative results. Focus on deliverables also helps us avoid becoming enamored of a technique or product that sounds wonderful but doesn’t really improve our security. If it doesn’t produce the desired effect, then it doesn’t matter what a good deal we got or how nice the sales guy is or how minimally disruptive the run-time characteristics of the product are. Out it goes.

Targeting—although some elements of a security awareness program may be suitable for all users, there will always be specific groups whose needs don’t fit the generics. Identifying the target audience segments is a crucial part of starting a program, and modifying the target segments as business needs and security realities change is an equally important function in an ongoing program. The security message must also be crafted for the particular target segments. That might mean slight or major changes in examples, delivery style, or emphasis.

Audience segments—these may be differentiated by size, location, or availability, but there should be a specific set of awareness and training objectives for each target audience segment. For “mixed” segments (e.g., all employees at loca- tion A, even though their security responsibilities are different) the topics and delivery must address the security needs of each subgroup represented in the segment.

Delivery vehicle—the mechanism chosen to get the message across to the target audience. Among the most used are

◾ Briefing—please don’t make it a 4-hour “brief”ing. ◾ Formal presentation—usually for upper management. Spelling and gram-

mar are crushal…er, cruscial…er, crucial. Errors will be noticed much more than the content.

◾ Lecture—not used very much, but good for techies needing to know the specifics of new technologies or the detailed workings of complex threat and vulnerability scenarios. Digging deep is encouraged.

◾ Workshop—put them to work and they’ll get more out of the class. But make sure that the workshop situations reflect real-world possibilities and constraints. Too much blue sky and the exercise loses effect.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

98  ◾  Information Security Fundamentals

◾ Seminar—more relaxed, less formal. The focus here is on the exchange of ideas and building on the ideas of each participant. Better suited for long-term security items than immediate, pressing issues.

◾ Case study—especially good if they’re internal. Sanitize by using fictitious names because you don’t want to embarrass anyone; just get the message across. Case studies of other companies or agencies must be clearly rel- evant to your shop.

◾ Hands-on lab—excellent for training on new security technologies, but the commitment in resources and people is very steep. There must be monitors in the room to make sure that no one falls behind the pace of the primary instructor and that everyone in the class understands not just what to do but why this step follows that one. Equipment used should mirror what people will use in a production environment and be kept up-to-date.

◾ Theme—a catchphrase or motto or some unifying element that lets peo- ple know that this message, video, trinket, or sound bite came from and is associated with information security. Fairly common ones include “You are the key” and “Security begins with you.” You can certainly be more creative.

◾ Logo—may be a certain typeface, mascot, created cartoon character, or color combination for messages. Again, as in the theme, we want some- thing that clearly identifies the communication as emanating from and being about information security.

◾ Reinforcement—exercises or examples to strengthen the original security message. Hitting your point from several angles and several ways makes it much more likely to be remembered.

◾ Effectiveness measurements—these must be related to the behavioral change objectives of the program. Management wants to know if they’re getting bang for the buck. Is the awareness program making us more secure?

◾ Organizational culture—this is especially evident and influential in larger organizations, but it can also rear its head quickly in small- to medium- sized organizations. If awareness thrust or a security program seems well thought out, reasonable, and effectively managed yet still gets poor results, look for some aspect of the program to be violating organizational culture. The culture might not be explicitly stated or published, but it will permeate the entire enterprise.

◾ Group norms—they might be related to organizational culture or to the dominant profession in a department. They delineate acceptable behav- iors and specify what one shouldn’t do. All too often, our proposed secu- rity measures tread on some group norm and evoke surprisingly fierce resistance. We must learn the group norms before trying to change group behavior.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  99

◾ Dominant profession—there are organizations dominated by engineers, others driven by marketing or sales; universities should have academics as a dominant profession. It’s quite possible that different departments of an organization have their own dominant professions. Knowing what they are makes it much easier to tailor an awareness and training program.

◾ Informal organization—as opposed to the published organization chart, this refers to the people in departments who aren’t listed as leaders, but whose example tends to be followed by other workers. An informal orga- nization leader may be an executive assistant, an experienced line worker, even a part-timer. From an awareness perspective, identifying the infor- mal organization and getting its leaders to buy into security plans can smooth the delivery and vastly increase the acceptance level of proposed changes.

Rationale Why We Need Information Security Organizations depend on networks and computers. Yours is no exception. Computers and multiple other devices of varying kinds store and process data and information, which is an asset and which can be critical or sensitive. Compromise or loss of information or inability to process it have associated costs.

◾ Replacement—costs associated with recovering or reproducing and restaging data and information so it is once again usable for business purposes. This is what usually gets listed as the cost of data loss, and it can be substantial, but it’s not the full and final cost.

◾ Availability—because the data were unavailable at a certain time, we couldn’t perform some actions that depended on it. Some of the actions may be con- tractually mandated or legally required and could lead to fines or lawsuits or other penalties. We may also miss chances for significant profit (see Opportunity).

◾ Confidentiality—are items that were supposed to be kept secret. If not, which ones got compromised and to what level? Who do we have to notify about confidentiality breaches? How do we tell them? What does it cost? What does it do to whatever trust relationship we have tried to build with that customer, supplier, or partner?

◾ Integrity—if someone unauthorized has been in a database, can we still trust the content? Integrity checks, run to make sure no unapproved or undocu- mented changes have been made, take time and resources.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

100  ◾  Information Security Fundamentals

◾ Opportunity—in addition to missing opportunities for profit, we’ll usually assign our best people to investigate and clean up one of these incidents. That means that our stars are not working on future architectures or technologies or potential products, but digging around in the debris of an incident. We’re not getting maximal use out of their talents.

How much information gets lost in natural disasters? How much in terrorist attacks? How much credibility does an agency or company lose in a data breach? What do privacy breaches cost schools and private sector firms?

Good management (not just Sarbanes–Oxley or Basel III, or FFIEC, or SAS- 70, or GLB, or ISO 27001, or ITIL or PCI DSS or whatever new regulations come along) demands accountability at several levels.

◾ Customer—should know what data they gave and when they were given. Should also have an idea of the value of individual pieces of data that can be aggregated into significant information.

◾ Owner—usually the creator of the data or the manager of the area where the data were created.

◾ Trustee—this is usually the IT group or the database group. They don’t own the data, but they are entrusted with its care.

◾ User—the internal customer of IT who actually uses or manipulates (or both) the data for business purposes.

◾ Guardian—not just IT security. Whoever has access to the data has some responsibility for guarding it and keeping it from unauthorized disclosure.

◾ Database Administrator (DBA)—the responsibility here is not that of the owner, but to make sure that the data warehouse or database system main- tains data integrity and that the data can be trusted.

◾ Webmaster—again, not usually the owner or creator of data, but responsible for seeing that web controls are adequate to protect what needs to be protected.

◾ Administrator—for accurate and timely implementation of access control to data as approved by the owner.

What Is “Awareness,” Anyway? It’s what makes people feel, think, and do. The sensitization or feeling part is vis- ceral, elemental, instinctual, and emotional. The education or thinking part is intel- lectual and mental. The training or doing aspect is physical and hands-on, related to employment. The bottom line in all of this is summed up in the following equation:

Knowledge + motivation = behavior

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  101

Why IT Security Awareness? People are the biggest threat. We get crime by the discontented: errors by those who are careless, pressured, distracted, iPadding, iPodding, cell phoning, misconstru- ing, multitasking, desensitized, or socially engineered.

Computers, networks, and information are hard to control and manage. We have errors and crime occurring at the speed of light. We face complex and chang- ing technology. The client/server revolution freed the users, but complicated the security professional’s world by giving us not just distributed but also dispersed networks located in uncontrolled, user-managed areas and featuring minimal audit trails. In the second decade of the twenty-first century, we have wireless everything, ever-increasing connectivity, and devices that simultaneously get smaller and hold and do more.

Making Awareness Happen Appoint an Awareness Team We’ll need a multidisciplinary team for several reasons. The problem is complex. Security is viewed as overhead, and rightly so. It also crosses lots of corporate turf. Even though there is inherent awareness of the need for and value of security, peo- ple in all departments have heavy workloads, and we need their support, expertise, and knowledge.

The makeup, level, and size of the security awareness team will also vary with different organizations. Among those to be considered for membership are

◾ Information Systems Security—obviously. ◾ Physical Security Manager—getting more important as sizes of devices

decrease and capacity increases. ◾ Computer users—because we’re going to ask them to change, they ought to

be represented and have a voice in the changes. ◾ Recovery group representative—contingency planning and business conti-

nuity/resumption must be addressed. ◾ Training expert—for guidance on how to structure and deliver our messages. ◾ Specific area managers—for good examples and for those areas that really

need substantial change. ◾ Legal—increasingly necessary in the age of compliance, but don’t let them

turn your team into a debating society. Might consider bringing legal in only when their advice and counsel is recognized to be needed by the rest of the team.

◾ E-commerce group representative—as more production applications become web-facing or web-based, their input and buy-in is critical.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

102  ◾  Information Security Fundamentals

◾ Web developer—it’s a lot easier to build security into new web applications than to add it on when the app has gone into production.

◾ Human Resources—so that we assure adherence to policies and don’t create ones that are unenforceable.

◾ Corporate Communications Group—these people know how to effectively get the message out to all corners of the organization in an effective and efficient way. Through in-house publications and communications directed at share- holders, customers, employees, etc., they can help us adroitly express our ideas.

◾ Other—depends on the organization.

Part of the reason to staff the team with people from various departments is to ensure that you tie plans to organizational goals. The objective is commitment plus some degree of standardization.

Translate Goals into Action Plans Whether the awareness team is to be full-time or part-time, they need to translate goals into an action plan. To do so requires asking several questions:

◾ Who needs security awareness training? Managers, first-line supervisors, end- users, IT people, “all,” contractors, part-timers, admin people, and so on.

◾ How should they change? Just what behavioral changes do we want to see in each target group?

◾ What must be learned? If they’re going to change behavior, they probably need to learn a different way of doing something.

◾ What techniques are best? How do we get the new methods across effectively and efficiently?

◾ How to sell and budget the program? Obtaining and maintaining management buy-in and support are always challenges, and even if the initial support is strong, we can’t assume continued funding.

◾ When to implement? Usually, the answer is “now,” but sometimes it’s wiser to wait until another large-scale project completes or reaches a definitive mile- stone. But we can’t let the awareness efforts keep getting put on the back burner.

◾ What to monitor and track? It’s easy to measure how many people attend the sessions or perform the computer-based training, but what we really want here is based on the behavioral objectives of the awareness program. Did we actually get the changes we were looking for?

Targeting the Program A “generic” security awareness program sounds about as dull as it usually winds up being. To really reach a specific audience, to really get the behavioral changes needed to improve security in the organization, specific target audience segments

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  103

must be identified, fine-tuned, and periodically adjusted as conditions and priorities change. Although there are no school solutions or etched-in-stone rules for deter- mining who the target audiences are, here are some suggestions and guidelines.

Information Technology Providers—those who envision, develop, test, install, repair, patch, maintain, tweak, implement, remove, replace, explain, document, and answer questions and complaints regarding IT systems are definitely targets for the awareness program. And don’t forget the people who audit and secure the systems. Different subsets of the IT provider universe will need different security elements emphasized, and the manner of delivery might be different. Techies usu- ally need all the gory details, sometimes down to the code instruction level or how this query is parsed by this subset of that system. A quick overview won’t do it for them. But if you start covering buffer overflow mechanisms and defenses with the IT help desk operators, you’ll be able to watch a glaze form over their eyes, even if they’re nodding their heads in seeming comprehension. These guys and gals want to know how to respond to user questions and what triggers indicate that the reported problem is, indeed, security related and should be referred to level 1, 2, or 3 in Department X or Y for resolution.

IT Customers/Users—this category includes almost everyone in the organiza- tion. These days, even the janitors are wired (more likely wirelessly connected) in. Anyone who interacts with information or information systems will need some grounding in appropriate information security concepts and procedures. If there’s an “all” category, this is it. Here’s where you might very well have security aware- ness and training elements that are applicable to everyone. Even so, the method of delivery might not be the same for “all.”

Information/Data Owners—a crucial target audience; but sometimes it’s hard to pin down who the “owner” of a specific piece of information is. This is especially complicated in the world of Storage Area Networks (SANs) and Network Attached Storages (NAS) and public or private or hybrid cloud structures, even though information ownership should have been clearly resolved before any migration to SAN or cloud or whatever. Once you do identify the owners, you must make them understand their significant security responsibilities. They generally decide who gets what kind of access to which sensitive information. To do this effectively, they need both a business and a security perspective. They’ll probably be well-versed in the business vagaries, so we need to make sure we emphasize security and relate it to the business reality they already understand.

All Managers—the group of “all managers” will, no doubt, include some of the owners referenced above, but also those people up the chain who don’t have a lot of contact with day-to-day operational information and procedures. However, the status of manager usually involves access to sensitive, sometimes highly sensitive material, and security mistakes by managers can be a lot more damaging than those by us working stiffs. Examples are all over the newspapers and nightly news. Managers also may get desensitized to the importance of specific information if they have it in front of them and talk with their peers about it for hours on end and

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

104  ◾  Information Security Fundamentals

for days, even months at a time. They’ll normally recognize the need for reinforce- ment of “handling sensitive information” components of your awareness program, but the training must not be patronizing. These people didn’t get where they are by being careless and unintelligent.

There are about as many ways to partition security awareness program audi- ences as there are organizations with a program, but here are a few more possibili- ties, outlined with possible subcategories into which you can assign specific people or groups

By computer knowledge ◾ Alpha-geek wizard—knows all, sees all ◾ Web-head, crypto-nerd, Mr. Forensics, etc.—deep knowledge in one or

a few areas ◾ Competent technician ◾ Application guru—might not be a techie, but can make one application

dance ◾ Fully functional user ◾ Infrequent user ◾ Neophyte ◾ “What’s an applet?” ◾ Former technical manager—Caution! Can be very dangerous. Technical

knowledge ages very quickly and not well. The tendency here is to overes- timate technical prowess and demand higher access level than is needed for manager role.

◾ Multiple clouds implemented at home ◾ “Wireless device of the month” club ◾ Had RFID and GPS implanted in the dog… and on the kids

By organizational function ◾ Personnel administration ◾ Finance/accounting ◾ Production/manufacturing ◾ Marketing/sales ◾ Research/engineering ◾ Customer service ◾ Order fulfillment

Because this is a fairly common partitioning scheme, here’s an example of how one organization—a bank—divided its awareness audience by organizational function:

◾ Demand deposits ◾ Commercial loans ◾ Trust

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  105

◾ Mortgage loans ◾ Investment banking ◾ Investor relations ◾ Tellers ◾ Audit

When partitioning by organizational function, some degree of additional slic- ing will almost always be required. Here, for example, is how one company breaks out their information technology function:

◾ Programmer ◾ Analyst ◾ Telecomm specialist ◾ Network technician ◾ LAN administrator ◾ IT security officer ◾ Manager ◾ Webmaster/web content developer ◾ Cloud implementer

In conjunction with or instead of organizational function, you can partition by organizational level, such as

◾ Senior executive ◾ Middle manager ◾ First-line supervisor ◾ Technician ◾ Business specialist ◾ Administrative assistant ◾ Clerical employee ◾ “The Masses”

The type/model of computer used can also be useful, but that changes so fre- quently that any example would be out of date before publication.

Employment status can be an effective delimiter, especially in an environ- ment bound by multiple contractual and legal obligations regarding full-timers versus part-timers versus contractors, etc. Here’s how one organization does that partitioning:

◾ Employee ◾ Contractor ◾ Temp

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

106  ◾  Information Security Fundamentals

◾ Co-op student ◾ Consultant ◾ Outsourcing firm employee ◾ Competitor employee on joint project ◾ Service/product provider ◾ Customer

Once the partitions are delineated, the next step is to determine approximately how many people are in each category. There might be 12 or 14 senior managers and hundreds, even thousands, in the general user category. To tailor the message and delivery style for optimal effectiveness, the size of audience “chunks” has to be factored in. Audience availability and scheduling, especially for the higher-ups, can be closely related to the size of an awareness audience partition.

Needed Skills The set of required information security skills for a particular awareness program target audience segment depends on several factors:

The job—how much and what type of information do they interact with and handle every day? How sensitive is the information they see and modify? What are the business consequences of an error or deliberate malicious act?

The environment—here, we’re talking about the business environment and the technical environment. What programs are running on what types of machines? Where are the crucial data physically located? What are the gener- ally accepted procedures for handling sensitive information in this industry?

Group culture—what drives this organization, and what sort of people work here? Is it an engineering-oriented firm, a service-based agency, a commodity manu- facturer? Is there a primary group culture—engineering, customer service, mar- keting, financial services? Knowing the group culture will provide a significant advantage when deciding what techniques to use in the awareness program.

Management—have they truly bought into the need for security and an aware- ness program? Do they follow the rules they approve for others? Do they understand the risks?

We often tend to classify our users as “generic,” but those generic “users” per- form very specific business tasks using computers: things like accounting, order entry, production scheduling, long-term planning, product design, customer ser- vice, market analysis, and a host of other necessary business activities.

Many use the computers and networks to perform several, usually interrelated, business tasks:

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  107

◾ Payables and general ledger ◾ Receivables and general ledger ◾ Order entry, parts inventory, JIT scheduling ◾ Sales results and marketing plans ◾ R&D testing and new product plans

Even though people are using the same basic application types, including spreadsheets, Word processors, project planners, database engines, messaging net- works, etc., the security ramifications of what they do with these tools and specifi- cally developed products and processes vary widely. That is what we must focus on when constructing a security awareness and training plan for our organizations.

Generally speaking, the more sensitive and valuable the data that people in a specific job work with, the higher the degree of security required. Security skills in a visible, critical position must go far beyond the awareness level.

Here’s a partial list of security skills that may be required for people working in your organization. Add or subtract from the list as you see fit:

◾ For actual or potential incidents − Prevention − Recognition − Response − Containment − Event correlation − Collection of relevant data − Reporting − Remediation − Cleanup(?) − Retraining

◾ Social engineering analysis and defense ◾ Desktop security ◾ Password discipline ◾ Physical security ◾ Privacy protection ◾ Wireless connection discipline ◾ Classified item markings and handling ◾ Compliance analysis ◾ Internet taboos ◾ Criticality recognition ◾ Recovery procedures ◾ Evidence collection and handling ◾ Threat identification ◾ Off-site security procedures

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

108  ◾  Information Security Fundamentals

Desired Outcomes Security awareness programs are aimed at producing behavioral change or rein- forcement. To measure the program’s effectiveness, we need to know what the desired change was and to what extent it was completed and internalized. Therefore, among the first questions to be addressed when implementing a program are “What specific behavioral changes are objectives of the security awareness program at this organization? How do we want people to change? How do we know that they’ve changed?” These are not always easy to answer, but there are some change category indicators that can help tell us if the program’s desired effects are taking place.

Change category indicators for training More frequent password changes More designed-in security features Fewer errors Use of provided features

Change category indicators for education Better password control Understanding of data value and sensitivity Security budget increases More security problems reported “Better” audits

Change category indicators for sensitivity Less fear of new devices Better attitudes toward security Better feel for the risks Acceptance of security measures Suggestions for improvements in security More questions asked Others(?)

Group Culture Group culture determines “allowable” behavior for members. It rewards confor- mity with group norms, whether or not they match organizational policy or sound security principles. Attempts to change the group culture invariably meet resis- tance. Challenges to group cultural norms tend to bring some form of punishment. Resistance to change can be minimized if the change accentuates a firmly held group value. The informal organization is often more important to address than the formal organization as it appears on a chart. Effective training must comprehend the differing group cultures within an organization to strike responsive chords. Change threatens informal power structures. Co-opt the informal organization

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  109

leaders. If they buy in, others will follow. Profession culture is sometimes part of a group culture, sometimes a separate variable. Profession culture can be a major component of the overall corporate culture. Several group or profession culture conflicts tend to arise in organizations:

◾ Engineers versus marketers ◾ Everyone versus bean counters ◾ Private sector versus public sector ◾ Techies versus users ◾ Security versus technicians(?)

Some professions have been notoriously difficult for security practitioners to work with:

◾ Physicians ◾ Research scientists ◾ Engineers ◾ Customer service reps ◾ Computer/network wizards ◾ University professors

This can be an issue wherever there is some preponderance of specialists. Security training must be cognizant of the profession’s norms, ethics, and ways of doing things

Network designers want technical details ◾ How a security mechanism works ◾ Resource requirements ◾ Interfaces ◾ Run-time characteristics ◾ Reality, not speculation ◾ Imprecise information will destroy your credibility

Sales reps want deal-closing leverage points ◾ How will this affect the customer? ◾ How can I sell it as a benefit? ◾ How does it differentiate us from competitors? ◾ No gory technical details ◾ Simple explanations ◾ Pictures

Program Content Factors We’re making progress. We’ve chartered our organizational awareness team, identi- fied our audience segments and put some preliminary numbers of people in each

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

110  ◾  Information Security Fundamentals

segment. We’ve decided how we want their behavior to change and have at least some clues as to how we’ll detect that change. Now, we must flesh out the program with appropriate content. The content for an information security awareness pro- gram varies widely and several factors affect this variation:

◾ Organizational needs—this should be the prime determinant for the content of the program. The difficulty is in pinpointing which organizational needs are most pressing, and the answer, all too often, is determined by internal politics rather than rational analysis. Nevertheless, someone in the higher echelons of management will usually give information security some guid- ance regarding what areas to address (data loss prevention, access control, incident response, social engineering defense, smart phone security, etc.) and this will point to definitive content.

◾ Audience segment—how big is the segment (dozens or thousands), how geo- graphically dispersed are they? Can we effectively get the message to them without dispersing security people to the winds? How available are they to participate in the training? How big a time chunk do we get with them? Are they techies, business types, managers, IT people? Does the organization’s assessment of the segment’s security needs match the perception of those in the segment? If they don’t think they need the training, its chance of success plummets.

◾ Time parameters—when should the awareness training program start? Right now, next week, in 6 months, after the Oracle conversion? We know how important security is and how necessary this awareness program is, but can we stop in the middle of the CEO’s pet project to march everyone on the project through our course? Maybe we can hit them with part of the full cur- riculum now and save the rest for after project completion. Maybe the CEO thinks like us and wants security baked into the project implementation.

◾ “Hot buttons”—this wasn’t a major issue when we planned and started the awareness program, but news stories or television/Internet coverage on for- eign government hackers or damaging data leaks or inadequate recovery procedures or Stuxnet-type malicious code attacks or whatever have gotten management heavily focused on one area that absolutely, positively must be addressed in our awareness program…right now. Please understand that this is not optional. When upper management experiences a hot-button item, we must react. And, yes, that means that something that we were going to do, something that was decreed an organizational need, will have to wait while we re-aim the awareness training to counter the hot-button issue.

◾ Budget—it’s not unlimited. We’re competing with other departments for scarce budgetary resources, so we’ve got to make the most out of what we get. Search internally for help with a topic before going outside to buy a product or for some consulting. But try not to skimp on something that really is an organizational need.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  111

◾ Availability of awareness resources (including personnel)—some content lends itself to self-study and little interaction with information security personnel. Some audiences prefer to take the bull by the horns and not be guided by security people as they learn what to do and how and why. In such situations, we can make our content available internally and track usage without a whole lot of hand-holding, question answering, and site visits. However, some con- tent requires and some audiences want to be shown via hands-on demonstra- tions exactly how the new security mechanisms work and what to do if they don’t work and what needs to be entered if this error message appears, etc. One-on-one training can actually be efficient for managers, especially upper managers, but it won’t work for an army of general users. Just as our bud- get is not unlimited, neither is our supply of people to deliver the awareness training.

Program content must be consistent with both organizational requirements and employee personal goals. To avoid justifiable grumbling and lingering resentment toward information security, we must make sure that we inform them before they are held accountable and explain why controls are needed and why particular ones were selected. We’ll get more and better cooperation if we express ideas in terms meaningful to the particular audience. It also helps if we can show how the con- trols we’re proposing can prevent problems that they have experienced. One more caution—don’t ignore the effect on their productivity. We will slow them down. Security controls do add steps to their normal routines. Don’t deny it or gloss over the operational effect. Instead, focus on the long-term, and how these security con- trols can prevent future problems or keep them contained and manageable.

Program Content Items

Policy—policies, procedures, standards, and guidelines are all valid topics, but don’t bore them to tears. Don’t forget to mention the teeth in policies— that violations may have severe consequences. In awareness contexts, we usually stress positives, but for policy violation consequences, we need to let employees know that the consequences are real and that they might be quite unpleasant. It might help to quote from the organization’s policy manual that “… violators may be subject to disciplinary action up to and including termination. The company will also fully cooperate with law enforcement regarding possible prosecution.” If there have been violations in the past, then a history of enforcement accentuates the seriousness of the issue.

Threats—the specifics change constantly, but focusing on the threats’ effects on job functions will keep them interested. Technical people will want and need details of perimeter incursion methods, stealth techniques, and damaging

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

112  ◾  Information Security Fundamentals

payloads. If there are available countermeasures, describe them. Tell them how to use the controls provided, where to get help, how to recognize an incident, how to report an incident, how not to destroy evidence, or how to recover from a problem. If relevant to the audience segment, describe pass- through attacks and possible contingent liability.

Horror stories—they’ve been a staple of awareness programs for decades, but must be used with considerable caution. Horror stories are certainly easy to find. It often seems that every day we see reports of a new data breach, hacking exploit, or lost device chock-full of sensitive information. However, if a story about industrial espionage is not relevant to the environment and specific target audi- ence of our program, it won’t move the program along toward the behavioral goals we’re looking to accomplish. If the description of a massive power out- age following the Supervisory Control and Data Acquisition (SCADA) system attack doesn’t seem plausible to our employees, it won’t register with them. Acts of God—fires, floods, storms, lightning—tend to be credible, but we have to make a stronger case for horror stories revolving around privacy violations or unapplied patches. We can use internal incidents but, once again, caution is strongly advised. Be careful about airing dirty laundry or embarrassing some- one who survived the debacle. For internal incidents, stress successful recovery and praise those who did things right. For any of horror story, lay out the plan for using it in the program. Decide which target group(s) could benefit, how to slant the story to be meaningful to them, how much time to spend on it, what format to use to deliver it, what the primary message is, and what we want them to do or stop doing or do differently.

Rewards—true or not, the perception of most employees is that we in security are always trying to find people doing things wrong so we can admonish them. Rewards for people caught doing the right thing can help change this image and let those receiving the awards know that their efforts are appreci- ated. Verbal rewards in a public setting, maybe with a plaque and citation to go into the employee’s permanent record, build goodwill and show that secu- rity can say thanks and that employees can make a difference. Certificates, mugs, pens, t-shirts, and assorted goodies can also be used as rewards. If the budget permits, attendance at a class or conference makes a strong positive impression, and the word gets around the organization quickly that these security guys can hand out some valuable stuff if you support their efforts.

Penalties—the other side of the coin for awareness programs is to cover the things that might happen if one doesn’t follow the prescribed procedures. The gamut of penalties might include verbal warning, written warning, loss of access, manda- tory training, loss of pay, reassignment, demotion, termination, and prosecution. This isn’t pleasant stuff, but it might be necessary to remind people in a particular target segment that their actions may have significant consequences. Try not to be too preachy when covering these penalties. The danger is that we’ll sound too much like their old stereotype of security and reinforce negative images.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  113

Legal ramifications—here, we’re not talking about personal penalties, but the effects on our business of the laws in places where we actually do or are look- ing to do business. We most certainly want to get the legal department to help with this, although it has happened that legal’s first indication that there might be issues came in an awareness briefing delivered by a security person. Federal, State, Provincial, County, and Municipal laws may all come into play. Criminal laws are slowly trying to catch up with technology, so our people need to know about developments in that sphere, too. If applicable to our firm, economic espionage laws are valid awareness program content. Cover the purpose, the requirements for relief and for protection of propri- etary data, and the mandates that must be followed. Privacy laws vary widely by location, but their importance gets magnified every day. If there is a Chief Privacy Officer at our shop, enlist him or her to give input on this topic.

Current guidance and policy—duties and responsibilities regarding several secu- rity areas can be selected for delivery to particular target audience segments. Whether it be computer, network, workstation, Internet, web, communica- tion, smart phone, wireless, physical, or laptop security, some group will need guidance in their duties and responsibilities.

Security procedures—people get so busy doing their primary jobs that they often forget or ignore or bypass the security procedures we know are necessary. Content of an awareness program can almost always include some coverage of security procedures such as

◾ Password handling ◾ Security labeling ◾ Logging procedures ◾ Handling sensitive items ◾ Using security features ◾ PC practices ◾ LAN protection ◾ Network access and control ◾ PKI

Other potential topics ◾ Data integrity ◾ Information criticality and sensitivity ◾ Information accountability and ownership ◾ Quality control ◾ Risk management ◾ Contingency planning ◾ Physical security ◾ Personnel security ◾ Auditing ◾ Documentation

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

114  ◾  Information Security Fundamentals

◾ Local union rules ◾ Merger partner security status and philosophy ◾ Outsourcing and security ◾ Telecomm and networks ◾ Security troubleshooting ◾ Where security resides ◾ Encryption ◾ Identity validation

The following is an awareness program topic list used by an actual agency. Based on their needs, budget, scheduling availability, and several other items we discussed earlier in this chapter, the agency decided to focus on their “Top 14 areas”:

◾ Know your ISO ◾ Passwords ◾ Confidentiality ◾ Privacy ◾ Backup ◾ E-mail ◾ Viruses ◾ Incidents ◾ Cyber-security in infrastructure protection ◾ Social engineering ◾ Authorized use ◾ Privacy, security, and mission ◾ Computer disposal and confidentiality ◾ “Reply to all” on e-mail

Granted, there are a lot of topics listed, but not everyone got every topic. The “reply to all” on e-mails was actually aimed at two groups, which both seemed to think that this was standard procedure. In awareness presentations to other staff, the topic was barely mentioned, and produced some knowing smiles and head nods. The social engineering defense section was short for some of the audience segments but very detailed and example-filled for the help desk and for those who regularly interacted with the public. Everyone got schooled on how privacy and security fit into the mission of the agency, and everyone got some degree of coverage on passwords, incidents, and e-mails.

Degree of Detail The preponderance of topics leads us to the next step in architecting an effec- tive awareness and training program. For a specific topic and for a specific target

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  115

audience segment, what degree of detail do we need to deliver? Several factors point to an answer for this.

Depth of coverage—how deep do we need to go on this topic for this audience? If they really don’t need it at all, then none is the answer. If it’s of interest to them, but not cru- cial, we can probably get by with general coverage, but still be ready to answer questions that may arise. If this is an area of significant concern to this audience, or if it should be, despite what they think, then we must dig deep and provide detailed coverage, replete with examples and explanations and whatever else it takes to make the security point, get them thinking seriously about the topic and effect the behavior changes we seek.

Duration of coverage—this will be based on the depth needed, as described above. But there are some other variables that affect duration. The complexity of the topic may preclude a 30,000-ft. view or mandate one. If the audience segment needs in-depth understanding, we must take the time to cover all the bases. Management doesn’t want to read the code, and their eyes will glaze over if we start comparing encryption algorithm strength and methodologies. Audience availability is an important deter- minant of coverage duration. Shift workers and management are the most difficult to pin down for face-to-face training, and the time we get with them is always limited. Economics enters the picture when we’re trying to get senior managers to allocate time for training on laptop security or use of encryption or some other procedural security item. Financial managers also view awareness training from a somewhat different per- spective. To them, a one-hour awareness session with 40 people in a room is a person- week of productivity. Our training had better be to the point and worth the effort.

Locating Resources and Information If the target audience universe is small, if we’ve got access to effective technology, if our staff in security is adequate in number and training competence, if we can han- dle describing technical threats and countermeasures as well as business and legal issues, and if we’re not overburdened with other security tasks, then don’t worry, be happy. We don’t need help. So much for fantasy. We will need help; fortunately, there are many places where we can turn.

Internal Sources Before we go outside to hire consultants or buy products or services, see who’s knowl- edgeable and willing to cooperate internally. Sources for in-house expertise include

◾ Network designers ◾ Cloud implementation group ◾ System wizards ◾ Application gurus ◾ Virus response team

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

116  ◾  Information Security Fundamentals

◾ Webmaster ◾ Users who have been hit ◾ Legal ◾ Training experts ◾ Audiovisual/communications group

Of course, this is only a partial list, but here is where being nice to one or more of the über-geeks can really pay dividends. Most internal people willingly partici- pate with help and advice. Some will volunteer to give presentations or write scripts for others to present or white papers on favorite topics. Use them.

External Providers We’re probably not going to be able to get all the help we need internally. Reluctance, obstinacy, and competing commitments will see to that. So we then turn outward seeking enlightenment, guidance and help.

Local special interest groups—regional The International Information Systems Security Certification Consortium (ISC2), The Information Systems Security Association (ISSA) or The Information Systems Security and Control Association (ISACA) chapters, SANS mentor groups, etc.—generally are populated with professionals who are willing to both give and receive help. Joining one of these is an excellent move, not just for awareness reasons.

Security product vendors—yes, we know, they’re going to try to sell us something or up-sell us on what we already have, but for once, we want to know what techniques they use to sell the product. After all, we’re trying to sell the use of it internally.

Other users of the product—how did company A implement this, mesh it seam- lessly with their other systems, and get it to run smoothly? Vendors will read- ily give us contact information for those who have successfully implemented whatever they’re selling.

Web pages—if we dig, we can find a lot more than marketing material on some vendor web sites. Details, technical analyses, etc., are findable. On the other hand, for awareness purposes, maybe we want the marketing material.

Publications—security-oriented magazines, books, white papers, etc. Check Amazon, Barnes & Noble, etc.

Consultants—for specialized knowledge and for credibility with management. Training firms—check their catalogs. Sometimes, the outlines for their classes

can help you produce at least a partial training curriculum for a target audi- ence segment on a topic of interest.

Membership organizations—American Society for Industrial Security (ASIS), ISC2, ISSA, ISACA, etc.

Universities—Norwich and others have specialties in information security at both graduate and undergraduate levels.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  117

Pinpointing Areas of Deficiency These are areas where inadequate security measures or lack of adherence to security procedures have caused or can cause significant negative business effects. Locating these areas provides not only justification for the awareness program but also indi- cates who needs what kind of training. Past experiences drive this process, as do both internal and external audit reports. Regulatory feedback, even anticipation of regulatory feedback, can move items up on the priority list, as can penetration testing results. Consultant security reviews and security assessment product results should also point to deficient areas, but sometimes internal politics will trump any reviews or assessments. We may not agree with a politically motivated list of defi- ciencies and associated awareness priorities, but we must remember that manage- ment foots the bill for the program and can reorder priorities as they see fit.

Standardized measurements based on

◾ ITIL ◾ NIST Publications ◾ SAS-70 (Now SASE-16) ◾ ISO standards ◾ COBIT ◾ COSO ◾ FIEC ◾ Basel ◾ PCI DSS

These can help us prioritize our program. The trick here is finding consistent standards. It’s not that easy. With or without standards or assessment results, opin- ions play a major role in pinpointing areas of concern. Upper management has the final say, but we also may seek the opinions of area management, area workers, technical people, legal, the Chief Privacy Officer, the Compliance Group, or other security people. And don’t forget that we’re paid for our judgment. Our view might not be finally accepted as gospel, but our opinions on which areas need security shoring up is valuable.

Delivery Methods and Techniques No matter how well we know our audience, how specific we can be regarding what they need to learn and what behavioral changes they need to make, how much great information we’ve collected to convince them to change their behavior (or keep doing what they’re doing right)—unless we present it effectively—the desired outcomes won’t be reached. As technology continues to increase its rate of change, and as people become more accustomed to newer and newer forms of technology,

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

118  ◾  Information Security Fundamentals

we are challenged not only to concoct strategies to secure the new stuff but also to use it for our awareness efforts, thus demonstrating secure use. Even so, some of the relatively ancient delivery technologies still work, and can work well if used properly and for the right topics with the right audiences.

We certainly can’t cover all possible delivery mechanisms and techniques, but here is a sampling of ones that have been successful.

Presentations

PC projector—whether connected to a laptop or an iPhone or some yet-to-be- invented device, this has been the standard for quite a while. And it works, as long as it quickly and effectively hits the salient points and doesn’t drag on (death by PowerPoint). And PC projectors keep getting smaller, cheaper, and more powerful, which means we can keep the lights on in the room and see the faces of the audience. This helps us identify and interact with those who have questions but might be reluctant to ask them.

Flipchart—an ancient technology, but still a good one. Draw pictures, list con- cepts, offer the marker to an audience member so that they can clarify their question or situation. Used well, it’s an involving technology that gets people participating in the session.

Whiteboard—like a flipchart with automated storage and recall capability. Caution—don’t use permanent markers.

Webinars—can reach a large and geographically dispersed audience. They can also be archived for later reference or for those who were busy during the live webinar.

Intranet Web site—if we can get a specialized security web site on the Intranet, so much the better. Presentations from multiple internal and external sources can reside here.

No A/V aids—lawyers can do very well speaking to a group with no audiovisual aids. Very few others can. And the longer the presentation, the more the attendees want something to look at or listen to in addition to the speaker.

New-hire orientations—this can be a great way to present a positive impression of security from an employee’s first day. Keep it short, relatively light (don’t stress episodes of people who’ve been terminated for security violations), and give them contact information for security. Emphasize how security can help them get rolling with their new ID and access permissions. Smile.

Department meeting presentations—everyone wins. They get to fill the agenda for a weekly, monthly, or quarterly meeting; we get the attention of a specific department so we can tailor our security message to fit their precise situation.

Board of Directors’ presentations—board members might try to act casual, but for us as invited presenters, this is a very formal occasion. Make sure there are no spelling or grammar errors in the presentation. Make sure it’s not too long or too geeky, but be ready to answer their “technical” questions.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  119

Formal Security Courses It might be a stand-alone course or a section of an existing class. If it’s stand-alone, we might want different people from security or technical areas or user areas to cover different sections of the course. It could be focused on one product or one class of threats, or one critical issue. It might hit high points of weaknesses found in the latest security assessment and how to correct them.

If we can add a security component to an existing course, we might describe security add-ons that we’ve implemented for our use of the product. We can also cover how to use embedded or augmented security features. Use existing examples that are already in the course and tailor our security training to these examples. This minimizes the chance that we’ll alter the flow of the class or contradict other class material.

Demos Demos are great. Demos are dangerous. We can demonstrate threats, intrusion scenarios, mistakes, and accidents. We can show how easy it is to make a false assumption and proceed to open the door to our network. We can demonstrate countermeasures and show how they actually find and stop the probe or the attack. We can demonstrate to groups large or small, even one-on-one for senior manag- ers. But to be effective, the demo has to work as advertised. We’re not perceived as the brilliant, dedicated, courageous, dashing security gods we recognize in the mirror when we’re fumbling around and rebooting and trying to get something to run and saying, “Gee, it never did that before.” Therefore, here are four rules for demos:

1. Practice 2. Practice 3. Practice 4. Have a canned backup available to show what’s really supposed to happen

Purchased Videos or DVDs The purchased ones are usually divisible into segments, each emphasizing one pri- mary security element. Total time for the purchased videos runs close to 20 min- utes. This is not an accident. Security videos are not often Academy Award caliber. Our employees can handle maybe 20 minutes and still maintain some interest in the content, but beyond that, their minds wander. One way to avoid the 20-minute limit problem is to host “Brown bag theatre” sessions at lunchtime in a section of the cafeteria and show one or two segments of a video per session. It’s important to also have a security person on hand to answer (or ask) questions. And get some discussion rolling.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

120  ◾  Information Security Fundamentals

Internal videos and films—this is a major effort. It needs pizzazz to maintain interest, but can’t be too slapstick or too grim and somber. Scenarios must be believable. We’ve got to decide whether we’re going to use employees or actors in the roles. Someone has to write a script, and the 20-minute rule applies here, maybe more than for purchased videos. Too many home-grown videos try to cover too many topics. We need to keep it focused. And we need to be ever-aware of costs. Really bad ones will find their way to YouTube and be there forever.

Routings of relevant articles—the keys here are threefold: not too many, not too often, and relevance must be direct and obvious. If the security message is appro- priate, they can be articles about our organization, competitors, even companies in different industries if the parallels are real and visible. We can use horror stories or recovery sagas. This author prefers tales of recovery because they show that it’s not just possible to get into a bad situation, but also to survive it.

Trinkets—with a security message and an identity logo. The object should be at least plausibly usable. A partial listing of the trinkets seen (and collected) by your humble correspondent follows:

ceramic mug mouse pad stickers t-shirts

coaster envelope opener post-it notes ball caps

squeeze balls travel mug memo pads game tickets

wrist rest candy jar screwdrivers carry-all bags

pen paper clip holder pencils calendars

yo-yo’s light balls frisbees

White papers—these are detailed, security-related analyses of issues, threats, or future technologies that may be usable in your organization. Often, they are requested by management to address hot-button items. Sometimes, we’ll generate them in anticipation of such a request. The main things about a white paper are that it is a detailed analysis, not an introduction, a glossing over, or a quick hit on a topic and it delves into the topic from the perspective and in the context of our organization. And whether its topic is cloud-related, mobile device, privacy, end point security, or anything else, start with a one-page summary for manage- ment, and then proceed with all the gory technical detail the subject merits. The one-page summary, though, must be clear and concise and not contradicted by the detailed analysis. If we get the help of respected techies on these, they can be surprisingly effective in convincing management that we do need some security- related piece of equipment or software or that we need to adopt some new policy or procedure.

Posters—make sure they are visually appealing and placed where clearly vis- ible to the intended audience. Color helps, and regular rotation (at least monthly)

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  121

prevents them from going stale. If we have a distinctive security logo, make sure it’s prominent on the poster. Depending on the corporate culture, amusing posters can be good spurs to memory. However, please be careful using humor in posters because there are some people in high places who think that a light approach to security issues is highly inappropriate. A final caution—emphasize one message on the poster not a laundry list of security to-do’s.

Guest speakers—expert speakers can bring interest to an otherwise dull discus- sion. Before going outside to hire a professional speaker on a security topic, check around inside the organization. We’ve probably got an expert somewhere in the technical group or legal or in one of the business groups who can not only cover the desired topic but also deliver the presentation from the perspective of our firm. Although sometimes, it does make sense to get an outsider to come in. The think- ing is that the external expert has seen many more organizations and can bring a broader perspective to the topic. That expert should also be free from internal political influences, and therefore, should have no axe to grind. Security special- ists can make very good guest speakers, as can motivators. Although with pure motivators, we must make sure that they know the security agenda we’re trying to pursue.

Publications Security awareness efforts are materially assisted by publications, whether they appear on paper or electronically readable form. Manuals for the security of exist- ing applications can supplement inadequate vendor documentation. Guidelines can give examples specific not just to the organization but also to the awareness audi- ence segment targeted. Reports let management and the rest of the firm know what happened during an incident or how we’re doing in relation to goals and objectives. Pamphlets give quick coverage of an important issue. Bulletins and incident alerts provide an early warning system for serious threats.

Newsletters—there are some that we can buy from vendors, usually with some degree of customization allowed for our needs, but many awareness programs that feature newsletters build and publish them internally. There are two pri- mary characteristics for security newsletters—short and regular. Don’t try to produce a 16-page security newsletter monthly, or even quarterly. Two to four pages will suffice, and try to stress positive items rather than how some- one in the organization really messed up. Mildly amusing incidents are okay, but don’t embarrass any employees. The newsletter can also cover interpreta- tions of laws, incidents, policies, etc. In lieu of writing a complete security newsletter, we can try to get a regular column in an existing “house organ” publication.

Intranet e sites—these have proven to be excellent resources for awareness and training programs. There are four primary objectives for a security intranet

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

122  ◾  Information Security Fundamentals

web site. And all of these objectives must be attained for the site to be successful:

◾ Interesting: if we put visitors to sleep, they won’t come back ◾ Relevant: deal with our issues, not generic, blue sky, or some other firm’s

issues ◾ Timely: analysis of attacks from 2008 won’t really help us. Keep informa-

tion current ◾ Protected: if it gets breached, the embarrassment quotient is very high,

and our credibility takes a major hit

There’s no end to the things we can put on a security intranet web site. Among the more popular items commonly found are

◾ Pointers and links to other items: policies, articles, books, web sites, etc. ◾ Contests, quizzes, and prizes ◾ FAQs: this can save us a lot of time answering the same questions over

and over ◾ Security survey forms ◾ Contact information for security personnel

− Names − Phone numbers − Office location − Pictures − E-mail addresses − Areas of specialization − Backups: in case the primary person is unavailable

Policies Text Pointers Interpretation Examples Reasoning behind Draft new policies Solicitations for comments

Procedural guidelines—keyed to our specific work environments, with sequential steps and rationales, if possible

Security news—cull for things that are relevant to our organization Incident bulletins/recaps/analysis Security quarterly reports—with associated red, yellow, and green charts and

dashboards White papers—in all their glorious detail Internal security job postings Internal security newsletter Details of horror and success stories—sanitize them to prevent embarrassing employees

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  123

Testimonials—from those who got hit by malware, made a mistake, or were socially engineered. If the person who experienced the problem is willing to describe it, this can be a very powerful training and attitude adjustment tool for others. Reader comments (don’t filter, except for language) Incident reporting forms and instructions Checklists (e.g., hacker incident response, possible virus, physical security

incident, etc.) Web-based presentations (e.g., “Getting Connected Securely,” “Our

Firewalls,” “Using iPads Securely,” “Smart Phones and Security at XYZ Corp.”, etc.)

Recovery plan information—not heavy details here but an outline and where to go to find the details for different departments

Audit emphasis areas—if the areas know what audit will be looking at, and they shore up the security of those areas before the actual audit, it isn’t cheating, it’s improving the security of the organization

Even before we decide what will be included in our Intranet Information Security Web site, we should focus on the architectural elements, then the graph- ics. Please don’t forget that users will not often visit someplace that features text, text, and more text. Think about what inducements we will offer to increase read- ership. Plan to prevent and recover from defacements. Decide whose help we’ll need outside of the security department and how we’ll get them interested in helping us.

Small Pamphlets and Booklets These are almost always short and to the point. Successful ones have used card stock paper, colored stock, tri-fold sheets, and specially created odd-sized paper stock. They’re dedicated to one topic, and give bite-sized nuggets of information to help users, managers, and technicians prevent and respond to problems. They also feature the security logo and motto (if there is one) and information on how to quickly contact IT Security. Among the topics that have been used for such publications are

◾ Local laws ◾ Securing sensitive information ◾ Things you should know and do when traveling with your laptop ◾ Systems security reference (what, where, and who to call…) ◾ Sarbanes–Oxley and you: a guide for managers ◾ Emergency procedures ◾ Desktop security handbook ◾ Administrator references

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

124  ◾  Information Security Fundamentals

This is certainly not an exhaustive list. The possibilities are almost infinite here. Just remember to keep it short, interesting, colorful, and focused on specific dos and don’ts.

Formal Courses If one or more formal classes on security topics are to be part of our awareness pro- gram, several items must go into the planning, implementation, and operational phases. Selecting topics and deciding on exact content comes first. Then, we must lay out a sequence and format for the course and decide whether we’ll take material from existing courses or do unique development for this one. We’ve got to plan for resources, such as teachers, facilities, visual aids, handout materials, and possibly computers for each student. Depending on the duration of the course, we could need to schedule refreshment breaks or lunches (or both).

We’ve also got to determine

◾ Timing—what time of year or business cycle do we initiate and deliver the class?

◾ Duration—will it be 1 hour, a half-day, a full day, 3 days? ◾ Frequency—how often do we repeat it? ◾ Scheduling—who goes to which class when?

The topic, exact content, audience, and time available will help determine pre- sentation style. We defined these back in the terminology section, so we’ll just mention them here:

◾ Briefing ◾ Lecture ◾ Seminar ◾ Case study ◾ Workshop ◾ Hands-on lab

Sometimes, we’ll decide to use a mixture of presentation styles, taking the best elements of several, perhaps adding some reinforcement exercises to augment learning.

There will be some additional resources we’ll need for a formal course. Some easy to locate, others more complicated. Classrooms may be available at our site, but we may want to have the course off-site to minimize distractions and having students being called out of the class for trivial reasons. Scheduling classrooms becomes just as important as scheduling attendees.

Capacity—we’ll need a room that comfortably holds the scheduled number of students, preferably with some extra size and chairs and tables for late sign-ups

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  125

or people who missed the last iteration. For most classes, the configuration called “classroom,” with a chair and table spot for each student and all facing the front of the room, will be just fine. But some seminars and classes featuring a great deal of interaction may be better served with the “U-shaped” configuration, teacher and projector in the opening of the U. On-site will no doubt be the least expensive location for the class, but scheduling gets complicated, and it has happened that a security class was told to vacate the room in the middle of the session because there was “an important meeting” that just got scheduled and needed a venue. If we go off-site, we need to budget for the room, A/V, refreshments, and possibly transpor- tation of our people to and fro.

Hands-on labs can be very effective training solutions, but they’re certainly not cheap. We’ll need:

◾ Workstations ◾ Network connections ◾ Student IDs ◾ Scripted scenarios ◾ Extra instructors for monitor duty ◾ Specialized A/V

And for any formal class, if we’re going to give the students a paper handout, we’ll either have to develop it or contract out the development or buy a textbook that works for the class. If we want to reproduce some supplemental materials, we need to check copyright issues. If we want to add some relevant books (dead-tree or e-books) we’ll need funds, lead time, and a logistics plan.

An Intranet web course or quiz can be an interesting awareness project. Some organizations that use them require passing the quiz to access the network. If so, make sure it’s short and that security is available to help if someone thinks they should have passed and really needs to get to some data. A few considerations for an Intranet quiz:

◾ Who writes it? ◾ Who takes it? ◾ Needed score for passing? ◾ Grading? (Yes or No or P/F?) ◾ Maintenance—who keeps it up-to-date?

Special Events Special events can energize a program. If done well, they show management’s inter- est and raise the excitement level for everyone. An awareness event doesn’t need to be elaborate, but it can allow the security team’s creativity to manifest itself.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

126  ◾  Information Security Fundamentals

Campaign kick-off meeting—possibly off-site. One of the most effective ones this author has seen was held in a city museum that the company had rented for the day. Keep the pace up; make sure it doesn’t drag. Be judicious in choosing speakers for the kick-off. We definitely want some C-level manager to start the festivities and show support. If budget allows, bring in an industry guru as a guest speaker. Focus on current, relevant issues and give a quick preview of planned awareness activities for the next year. Presentations may need to be repeated for shifts/office coverage.

Security awareness fair—these are more casual than the awareness campaign kick-off events, but they can feature more interaction for the target audiences. A security awareness fair might last 2 or 3 days and include displays (usually near cafeteria), security videos, vendor representatives, giveaways, contests with prizes, demos, and hands-on displays.

Security awareness day—same as the fair, but on a smaller scale. It’s important that the event be informal and nonthreatening for the employees. Food helps (if you feed them, they will come), as do guest speakers from technical or business areas.

Road shows—logistically, these are more complicated, but they show the remote sites that they’re not forgotten and that what they do really matters. Bringing the word to remote sites, even if it’s the same general message demonstrates interest on the part of security. And if we use their people as guest speak- ers, we can tailor the message to the specific site, function, etc. It’s also very important to encourage questions and answers.

Selling the Program Unfortunately, information security doesn’t sell itself. One of the first tasks for a security awareness program is convincing management and the organizational population that the effort is indeed necessary and fruitful. From the information security viewpoint, what we want is for information security to be a normal and accepted part of the organizational culture. There are some strategies we can use to achieve this.

Link to corporate goals—this is the absolute best way to ensure that there’s a reasoned, adequate and coherent answer to the inevitable question “Why?” When we can tie an awareness event or thrust or subprogram (such as data loss prevention tools and techniques for those using web-facing apps) to a specific organizational goal (e.g., 30% of profit from web-based commerce by the third quarter next year), justification for the awareness effort becomes almost self-evident…almost. Linking to goals presupposes that we know what the goals are and when they get altered. It also means that we have to be ready to change our priorities when the goals are “readjusted.”

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  127

Focus on the information asset—even though the threats might be to reputation or market position, our focus must be on the information asset and how com- promises or damage to that asset can lead to negative consequences, or how effectively protecting and using information can help service levels or com- petitive advantage. Yes, we need to take the business perspective. But we must also explain to target audiences how the information we want them to protect affects the business. Focusing on the information asset also means emphasiz- ing (and praising) what they’re doing right so that they keep doing it.

Do at least a cursory risk analysis—it doesn’t have to be formal, detailed, expen- sive, or time-consuming, but look around and analyze what’s going on. Use your own experience as a baseline. Ask why things are done, and why this way, and what controls come into play, and who controls the controls, etc.

Check what others are doing—other departments or sites might be facing similar security challenges. Learn what to do or what not to do from them. Some unique characteristics in the target department or a compared one may make a control especially relevant or completely unusable. Competitors, even companies out- side your industry, can also shine light on approaches to solving our problem.

Prepare for the future—last year’s program might not be relevant this year and probably won’t generate interest next year. Keep up-to-date with technology and business thrusts.

Understand their worldview—it’s not limited to their department, but their main busi- ness focus is their department and how it fits into the organization’s overall goals.

Speak their language—standard business English, not security geek talk. Sell the benefits to them of the awareness program—of course, you must speak

their language and understand their worldview to do this.

Dealing with Management Without their support, there is no security awareness program. Managers have access to extremely sensitive material. It’s possible for them to become desensitized to information’s sensitivity. Managers also set the example, whether they want to or not. If they give only lip service to information security, it tells everyone else that the subject is not really important. This is one reason why management is such a crucial target audience segment for any awareness program. One-on-one training sessions might sound extremely profligate, but they could be a very effective mecha- nism for dealing with this target segment.

To get their support, use terminology familiar to them:

◾ Cost–benefit analysis ◾ Expenditures in terms of

− Money − People

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

128  ◾  Information Security Fundamentals

− Resources − Payback and effect on mission

◾ Response to hot-button items (HIPAA, GLB, Sarbanes–Oxley, latest virus, terrorist defense, recovery, new laws, etc.)

“Required security skills” will depend on their judgment of how much security is necessary. You give input; they make the call. Handling sensitive information is usually an area where they’ll accept their need for training. However, their train- ing can’t be long and drawn out. Avoid getting bogged down in technical details, but be prepared to answer their questions in terms of their reality. They don’t want themselves or the organization to be embarrassed.

Do not patronize them. This can be dangerous to both you and the awareness program. Managers didn’t get to where they are by being careless or stupid. They may not have information security expertise, but they know how the organization works and how to get things done. Management is generally receptive. They’re a good, responsive audience who will keep you on your toes. Be prepared to answer questions, and allow some sidetracking.

Politics will be unavoidable in any organization with more than two people. Even if some specific security skills are very obviously required, your saying so might be construed as stepping on toes or an attempt at empire building. You can make a career-endangering statement without even realizing it. Be aware of politi- cal realities where you work. Try to avoid being used as a tool. If possible, find an “angel”—someone in high places who shares your perceptions and opinions regard- ing information security and the firm. But even with an angel, there are sometimes unpleasant surprises. Don’t overreact when a political decision guts or hamstrings your carefully crafted, business-justified security awareness training plan.

Maintaining Compliance To ensure continuing progress and avoid backsliding, we’ve got to put some steps in place to maintain compliance. Asking for suggestions can work remarkably well in resolving dilemmas and constructing compromises that provide adequate security and allow the work of the firm to continue with relative smoothness. Allying with audit helps them and us and makes the requests from both groups more consistent, giving less confusion to the general population. It also helps us follow-up for late- developing issues. Praise successes and those who help. We’ll get more cooperation down the road. Small security steps, rather than giant, traumatic leaps lessen the fear factor for those upon whom our controls get inflicted, and it’s easier to train people on small, gradual changes than massive upheavals.

Keep the program fresh by changing the style of delivery, the medium, or the particular message often. Consider the organizational culture; you’re not going to change it overnight.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Building an Effective Security Awareness Program  ◾  129

Final words: communicate, communicate, communicate. Bottom line—people will comply if they believe it’s in their own best interest

to do so.

Conclusion Security awareness is a complex, multifaceted, ongoing, ever-changing, high-tech, and high-touch proposition. It is vital to our organizations… now and in the future. Real enthusiasm is the key.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:41.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .