elements of an information security awareness program

21
Security Awareness

Upload: barry-caplin

Post on 15-Jan-2015

1.315 views

Category:

Technology


2 download

DESCRIPTION

 

TRANSCRIPT

Page 1: Elements of an Information Security Awareness Program

Security Awareness

Page 2: Elements of an Information Security Awareness Program

The Challenge of Security Awareness

Why?

Nobody cares about Security…

And how do we get their attention and support?

Page 3: Elements of an Information Security Awareness Program

Types of Risk

Prof. John Adams, University College LondonUK risk expert

• Direct – directly perceived – obvious• Scientific – determined via science• Virtual Risk – everything else!

Page 4: Elements of an Information Security Awareness Program

Types of Risk

Virtual Risk• What we are all involved in!• Project risk/Operational risk• Physical/Data security risk• Terrorism/Homeland Security• Weather

Page 5: Elements of an Information Security Awareness Program

Virtual Risk

Virtual Risk• Difficult to “prove”• Experts don’t know or do not agree• We don’t know what we don’t know

Page 6: Elements of an Information Security Awareness Program

Issues

• Security viewed as a negative• Avoidance v. “risk”

– Delays– Cost– Extra work– “Gotchas”

Page 7: Elements of an Information Security Awareness Program

10. Make Top 10 lists!

Top 10

The Top 10 things we do for Security Awareness at DHS…

Page 8: Elements of an Information Security Awareness Program
Page 9: Elements of an Information Security Awareness Program

10. Make Top 10 lists!

Top 10

The Top 10 things we do for Security Awareness at DHS…

9. Have a Mascot

Page 10: Elements of an Information Security Awareness Program
Page 11: Elements of an Information Security Awareness Program

10. Make Top 10 lists!

Top 10

The Top 10 things we do for Security Awareness at DHS…

9. Have a Mascot8. Dress Up

Page 12: Elements of an Information Security Awareness Program
Page 13: Elements of an Information Security Awareness Program

10. Make Top 10 lists!

Top 10

The Top 10 things we do for Security Awareness at DHS…

9. Have a Mascot8. Dress Up7. 1-on-1 Executive Briefings

Page 14: Elements of an Information Security Awareness Program

10. Make Top 10 lists!

Top 10

The Top 10 things we do for Security Awareness at DHS…

9. Have a Mascot8. Dress Up7. 1-on-1 Executive Briefings6. The Screensaver

Page 15: Elements of an Information Security Awareness Program

Top 10

The Top 10 things we do for Security Awareness at DHS…

5. Computer Security Day – comics and greeting cards

Page 16: Elements of an Information Security Awareness Program
Page 17: Elements of an Information Security Awareness Program

Top 10

The Top 10 things we do for Security Awareness at DHS…

5. Computer Security Day4. Publish or Perish

Page 18: Elements of an Information Security Awareness Program
Page 19: Elements of an Information Security Awareness Program

Top 10

The Top 10 things we do for Security Awareness at DHS…

5. Computer Security Day4. Publish or Perish3. Continually reinvent

Page 20: Elements of an Information Security Awareness Program

Top 10

The Top 10 things we do for Security Awareness at DHS…

5. Computer Security Day4. Publish or Perish3. Continually reinvent2. Get others to play

Page 21: Elements of an Information Security Awareness Program

Top 10

The Top 10 things we do for Security Awareness at DHS…

5. Computer Security Day4. Publish or Perish3. Continually reinvent2. Get others to play1. Have Fun!