In this post we deal with habit 1: Be Proactive
Please first read The Seven Habits of Highly Effective Security Plans [Part 1]
Please first read the Seven Habits of Highly Effective Security Plans [Part 2]
This is based on Stephen Covey's book The Seven Habits of Highly Effective People and in this post we look at how being proactive can help raise the general security of an organisation. This is applicable from a micro 1 person business to a multi-national company.
Being proactive really translates into taking ownership. There is a general feeling that Information Security is someone else's problem - usually IT. The thing is that even IT shelve the responsibility onto technology such as Firewalls, Antivirus and IDS boxes.
It has taken legislation in the United States and Europe (not so much in South Africa yet) to put Information Security risk back where it should be - the Business and by "Business" I mean non-IT people. Is this fair? Sure, it is their data and they must protect it from getting lost. Security is there to help and IT is there to make sure that the technology is there but at the end of the day if a spreadsheet with financial information goes missing - it is the department that owns the spreadsheet that is going to suffer.
Of course, all the three camps can be proactive. InfoSec can, should, must promote awareness of Security. They need Business and IT to understand what the dangers are and what is expected from a regulatory point of view. Posters, education, emails, etc etc can all be done.
IT can help by telling InfoSec of incidents that they may find, by making systems secure from the start, from being enthusiastic about patching and hardening servers and helping out with standards that are secure.
Business can be aware that it is information they use everyday that IT and InfoSec are protecting and the protection is for them so they can do their work more effectively which is what business is all about. They should strive to understand the tools that they use and how to use them securely. Strong passwords, clean desk policy, locking workstations, locking offices, thinking twice before opening strange files are all things that can be done for free and together are far more effective than anti virus, firewalls and NAC.
It is difficult to get the inertia going and people are reluctant to change but it is important to at least start working on a culture where information is seen as an important asset is protected as such.
I think this is lot more productive than playing each part of the business off against each other.
Showing posts with label training. Show all posts
Showing posts with label training. Show all posts
Friday, September 21, 2007
Wednesday, March 7, 2007
Confession time
Before I begin let me say that this post is about Information Security in a way and, yes, I did clean up the sugar.
I was at work yesterday and I made myself my usual morning cup of tea. On the way between the very cumbersome sugar bowl and the cup I managed to spill almost the entire teaspoon of sugar on the counter. Thats a lot of sugar. And a though went through my head - picture a tiny little version of me sitting on my shoulder dressed in red looking like a devil. "Walk away. Noone will know and someone will clean it up." A little angel popped up and told me differently and I did clean up the sugar but while I was finishing the cup of tea I wondered what factors did I take into account before thinking "naaah." And because I am always thinking Information Security (except at home - I love my family) how can I use this unexpected bit of evil in me for good.
When I spilled the sugar there was noone in the kitchen with me. Noone and I am sure about that. I was not being monitored and I know that too. Had there been someone there or just the possibility of someone there I would not have hesitated to clean up the sugar.
There is always some sugar on the counter because not all of it goes into cups - the sugar bowl is too tall. It is accepted that a bit of sugar on the counter is the norm and no-one feels bad spilling a bit of sugar, its almost expected. So, how much is too much?
There are cleaners that work in the kitchen and they would have cleaned up the mess eventually - if no-one else did first. So, the mess would have been cleaned up.
And lastly, I didn't have anything to clean the mess up with. I went to get a piece of paper and scooped the sugar onto the paper with my hand. And then put it all in the bin, but there was no tool for me to use that was designed for the job.
Another thing to consider, perhaps, is that its not my sugar or my counter. Maybe if they were I'd have been more careful.
Now, InfoSec. If your users are abusing your network it may be because
I was at work yesterday and I made myself my usual morning cup of tea. On the way between the very cumbersome sugar bowl and the cup I managed to spill almost the entire teaspoon of sugar on the counter. Thats a lot of sugar. And a though went through my head - picture a tiny little version of me sitting on my shoulder dressed in red looking like a devil. "Walk away. Noone will know and someone will clean it up." A little angel popped up and told me differently and I did clean up the sugar but while I was finishing the cup of tea I wondered what factors did I take into account before thinking "naaah." And because I am always thinking Information Security (except at home - I love my family) how can I use this unexpected bit of evil in me for good.
When I spilled the sugar there was noone in the kitchen with me. Noone and I am sure about that. I was not being monitored and I know that too. Had there been someone there or just the possibility of someone there I would not have hesitated to clean up the sugar.
There is always some sugar on the counter because not all of it goes into cups - the sugar bowl is too tall. It is accepted that a bit of sugar on the counter is the norm and no-one feels bad spilling a bit of sugar, its almost expected. So, how much is too much?
There are cleaners that work in the kitchen and they would have cleaned up the mess eventually - if no-one else did first. So, the mess would have been cleaned up.
And lastly, I didn't have anything to clean the mess up with. I went to get a piece of paper and scooped the sugar onto the paper with my hand. And then put it all in the bin, but there was no tool for me to use that was designed for the job.
Another thing to consider, perhaps, is that its not my sugar or my counter. Maybe if they were I'd have been more careful.
Now, InfoSec. If your users are abusing your network it may be because
- You are not monitoring them correctly
- You are monitoring but allowing small indiscretions through.. where do you draw the line?
- It is assumed IT or someone can fix the issues arising from stuff like installing Spyware etc.
- They don't have the training or the software in place to help them be secure.
- they don't feel security is their job and the company's data is not their asset.
Subscribe to:
Posts (Atom)