I was reading about Ralph Nader on Wikipedia, and came across something called the Pelzman Effect.
This is something I see a lot and I spend a lot of time in my induction meetings trying to work against.
The Pelzman Effect (named after Sam Peltzman, a professor of Economics) is when you are aware of safety controls.
Knowing that you are fairly well protected, you take more risky behavior. This essentially makes all the controls less valuable, worthless or actually creates more risk than if the controls were not in place.
Two of these controls (Firewalls and Antivirus) are important but they do not cover 100% of all risk and users need to know that they must not assume total protection but need to take some of their own precautions.
Backups are even worse.. they are not magical but they are assumed to be.
Showing posts with label awareness. Show all posts
Showing posts with label awareness. Show all posts
Tuesday, June 2, 2009
Friday, April 17, 2009
Analogy vs analogy. Let the games begin!
[Enforcement or Awareness? Whats best?]
Since my posting about how seatbelt legislation improved the use of seatbelts was very popular, I like the idea of traffic rules being used as an analogy for Information Security. So it was quite exciting to see some Gartner thinkers copying me (obviously they read my blog religiously, debate it at length and then copy it. I am that good).
So, the first one was about traffic light cameras causing more accidents than stopping them. And how the government won't remove them because they make some good money from them. Enough said there. The other was about how traffic speed signs have been around for years but not very effective but speed cameras are very effective.
Reading between the lines, it seems to me that the article puts down the idea of awareness in total as being not effective. Which is fair enough. In Information Security you can preach for hours but unless you actually capture the hearts of those in the room then you are lost. They will not listen. One way to go is to use a combination of things including awareness and enforcment.
Taking John Pescatore's analogy further - everyone stops at red traffic lights. Even when there are no cameras. It has become such a cultural thing that you don't even think "should I stop here?", you just do it. This is for two reasons. You understand that going through the traffic light when it is not your turn has a very big chance of killing you. Also - everyone does it. You are part of a cultural group that stops at the lights.
Awareness does work. But it needs to get buy in from people's minds and hearts. They have to Understand (note the capital U) why they do something and what the risks are. Once this is part of them then it spreads and becomes a cultural thing. Then you've won.
Since my posting about how seatbelt legislation improved the use of seatbelts was very popular, I like the idea of traffic rules being used as an analogy for Information Security. So it was quite exciting to see some Gartner thinkers copying me (obviously they read my blog religiously, debate it at length and then copy it. I am that good).
So, the first one was about traffic light cameras causing more accidents than stopping them. And how the government won't remove them because they make some good money from them. Enough said there. The other was about how traffic speed signs have been around for years but not very effective but speed cameras are very effective.
Reading between the lines, it seems to me that the article puts down the idea of awareness in total as being not effective. Which is fair enough. In Information Security you can preach for hours but unless you actually capture the hearts of those in the room then you are lost. They will not listen. One way to go is to use a combination of things including awareness and enforcment.
Taking John Pescatore's analogy further - everyone stops at red traffic lights. Even when there are no cameras. It has become such a cultural thing that you don't even think "should I stop here?", you just do it. This is for two reasons. You understand that going through the traffic light when it is not your turn has a very big chance of killing you. Also - everyone does it. You are part of a cultural group that stops at the lights.
Awareness does work. But it needs to get buy in from people's minds and hearts. They have to Understand (note the capital U) why they do something and what the risks are. Once this is part of them then it spreads and becomes a cultural thing. Then you've won.
Monday, April 6, 2009
The Conficker Eye Chart - Really!
This Conficker Eye Chart is brilliant!
Information Security can get a bit drab and boring. Especially when the auditors start poking around and you are arguing about the minutiae of your security policy. And especially when you look at the designers with their Apples and the programmers pumping out new Web 2.0 frontiers.
But sometimes, someone out there comes up with something so silly but effective that it just has to be blogged about.
The Conficker Eye Chart is simple - it tries to download images from Sites that Conficker blocks. If you can't see them then it could be that you are infected.
But you really have to see it. I wish I had come up with that one!
Information Security can get a bit drab and boring. Especially when the auditors start poking around and you are arguing about the minutiae of your security policy. And especially when you look at the designers with their Apples and the programmers pumping out new Web 2.0 frontiers.
But sometimes, someone out there comes up with something so silly but effective that it just has to be blogged about.
The Conficker Eye Chart is simple - it tries to download images from Sites that Conficker blocks. If you can't see them then it could be that you are infected.
But you really have to see it. I wish I had come up with that one!
Friday, September 21, 2007
Seven Habits of Highly Effective Security Plans [Part 3]
In this post we deal with habit 1: Be Proactive
Please first read The Seven Habits of Highly Effective Security Plans [Part 1]
Please first read the Seven Habits of Highly Effective Security Plans [Part 2]
This is based on Stephen Covey's book The Seven Habits of Highly Effective People and in this post we look at how being proactive can help raise the general security of an organisation. This is applicable from a micro 1 person business to a multi-national company.
Being proactive really translates into taking ownership. There is a general feeling that Information Security is someone else's problem - usually IT. The thing is that even IT shelve the responsibility onto technology such as Firewalls, Antivirus and IDS boxes.
It has taken legislation in the United States and Europe (not so much in South Africa yet) to put Information Security risk back where it should be - the Business and by "Business" I mean non-IT people. Is this fair? Sure, it is their data and they must protect it from getting lost. Security is there to help and IT is there to make sure that the technology is there but at the end of the day if a spreadsheet with financial information goes missing - it is the department that owns the spreadsheet that is going to suffer.
Of course, all the three camps can be proactive. InfoSec can, should, must promote awareness of Security. They need Business and IT to understand what the dangers are and what is expected from a regulatory point of view. Posters, education, emails, etc etc can all be done.
IT can help by telling InfoSec of incidents that they may find, by making systems secure from the start, from being enthusiastic about patching and hardening servers and helping out with standards that are secure.
Business can be aware that it is information they use everyday that IT and InfoSec are protecting and the protection is for them so they can do their work more effectively which is what business is all about. They should strive to understand the tools that they use and how to use them securely. Strong passwords, clean desk policy, locking workstations, locking offices, thinking twice before opening strange files are all things that can be done for free and together are far more effective than anti virus, firewalls and NAC.
It is difficult to get the inertia going and people are reluctant to change but it is important to at least start working on a culture where information is seen as an important asset is protected as such.
I think this is lot more productive than playing each part of the business off against each other.
Please first read The Seven Habits of Highly Effective Security Plans [Part 1]
Please first read the Seven Habits of Highly Effective Security Plans [Part 2]
This is based on Stephen Covey's book The Seven Habits of Highly Effective People and in this post we look at how being proactive can help raise the general security of an organisation. This is applicable from a micro 1 person business to a multi-national company.
Being proactive really translates into taking ownership. There is a general feeling that Information Security is someone else's problem - usually IT. The thing is that even IT shelve the responsibility onto technology such as Firewalls, Antivirus and IDS boxes.
It has taken legislation in the United States and Europe (not so much in South Africa yet) to put Information Security risk back where it should be - the Business and by "Business" I mean non-IT people. Is this fair? Sure, it is their data and they must protect it from getting lost. Security is there to help and IT is there to make sure that the technology is there but at the end of the day if a spreadsheet with financial information goes missing - it is the department that owns the spreadsheet that is going to suffer.
Of course, all the three camps can be proactive. InfoSec can, should, must promote awareness of Security. They need Business and IT to understand what the dangers are and what is expected from a regulatory point of view. Posters, education, emails, etc etc can all be done.
IT can help by telling InfoSec of incidents that they may find, by making systems secure from the start, from being enthusiastic about patching and hardening servers and helping out with standards that are secure.
Business can be aware that it is information they use everyday that IT and InfoSec are protecting and the protection is for them so they can do their work more effectively which is what business is all about. They should strive to understand the tools that they use and how to use them securely. Strong passwords, clean desk policy, locking workstations, locking offices, thinking twice before opening strange files are all things that can be done for free and together are far more effective than anti virus, firewalls and NAC.
It is difficult to get the inertia going and people are reluctant to change but it is important to at least start working on a culture where information is seen as an important asset is protected as such.
I think this is lot more productive than playing each part of the business off against each other.
Subscribe to:
Posts (Atom)