Skip to main content

Developing a Security-Awareness Culture - Improving Security Decision Making

CIOs, managers and staff are faced with ever increasing levels of complexity in managing the security of their organizations and in preventing attacks that are increasingly sophisticated. As individuals we are subjected to enormous amounts of information across broad ranges of subjects, including security policies; new technologies, patches and threats; and, new sources of information. As the environment continues to become more dynamic the process of making good security decisions is becoming more and more challenging. The answer lies in creating security-aware cultures in our organizations. This paper proposes that creating security aware cultures is dependent on improving how individuals make security decisions. Awareness of our decision-making processes as security practitioners can help us make better decisions in these uncertain conditions and help promote security-aware cultures in our organizations. Key to doing this is in understanding the process of how we really make decisions and what factors in the process may impair our abilities to make good security decisions for our organizations. This paper examines important facets of individual and group decision-making and provides prescriptive guidance on how we may improve the quality of our decision-making processes, leading to better security decisions.

1526 (PDF, 2.32MB)

18 Jan 2005
ByChris Garrett
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Metrics-Driven Information Security Framework as Part of Information Security Management

Research Paper

This paper presents a model of creating an actual accurate metrics-based security reporting model that is tied closely to the security management model used at the company.

  • 22 Mar 2022
  • Kirill Filatov

Denial of Service Deterrence

Research Paper

Denial of Service has been a very useful practice for attackers and continues to remain prevalent...

  • 1 Apr 2015
  • Ryan Sepe

Practical El Jefe

Research Paper

El Jefe is open source process monitoring software for Windows. With this tool, incident handlers...

  • 31 Mar 2015
  • Charles Vedaa

Using Influence Strategies to Improve Security Awareness Programs

Research Paper

Even companies with extensive, well-funded security awareness programs fall victim to attacks...

  • 25 Oct 2013
  • Alyssa Robinson

Talking Out Both Sides of Your Mouth: Streamlining Communication via Metaphor

Research Paper

As Security is a relatively new field, we are still learning how to communicate what we know with...

  • 4 Oct 2013
  • Josh More

Information Risks and Risk Management

Research Paper

This brief will cover the various exposures that companies now face as they increasingly rely on...

  • 1 May 2013
  • John Wurzler

Surfing the Web Anonymously - The Good and Evil of the Anonymizer

Research Paper

Companies of all sizes spend large amounts of time, resources, and money to ensure that their...

  • 8 Oct 2012
  • Peter Chow

Robots.txt

Research Paper

Although this GIAC gold paper is not about search engine optimization, or SEO, this paper will...

  • 31 May 2012
  • Jim Lehman

A Process for Continuous Improvement Using Log Analysis

Research Paper

Good security is a moving target. Walls and castles were once good defenses against attackers, but...

  • 26 Oct 2011
  • David Swift

Measuring Psychological Variables of Control In Information Security

Research Paper

The effects of an individual's personal feelings of control over aspects of their health have been...

  • 12 Jan 2011
  • Josh More

Which Disney(c) Princess are YOU?

Research Paper

Social engineering for identity theft has always been around. But now, with the advent of social...

  • 18 Mar 2010
  • Joshua Brower

Prelude as a Hybrid IDS Framework

Research Paper

Organizations both Large and Small are constantly looking to improve their posture on security....

  • 24 Mar 2009
  • Curt Yasm

The Importance of Security Awareness Training

Research Paper

One of the best ways to make sure company employees will not make costly errors in regard to...

  • 14 Jan 2009
  • Cindy Brodie

Vendor-Supplied Backdoor Passwords - A Continuing Vulnerability

Research Paper

Vendor-Supplied Backdoor Passwords - A Continuing Vulnerability

  • 26 Sep 2008
  • Astrid Todd

Making Security Awareness Efforts Work for You

Research Paper

Making Security Awareness Efforts Work for You

  • 20 May 2008
  • Rebecca Fowler

The Controlled Event Framework for Information Asset Security

Research Paper

The Controlled Event Framework for Information Asset Security

  • 20 Feb 2008
  • Chris Cronin

Data Leakage - Threats and Mitigation

Research Paper

Data Leakage - Threats and Mitigation

  • 24 Oct 2007
  • Peter Gordon

Identity Theft

Research Paper

The act of identity theft can be performed by anyone, it could be family, friends or spouses. The...

  • 2 Jul 2007
  • Ian Wolff

Social Engineering Your Employees to Information Security

Research Paper

This paper will examine the role and value of Information Security Awareness efforts in the...

  • 19 Dec 2006
  • Martin Manjak

Building a Security Policy Framework for a Large, Multi-national Company

Research Paper

Information Security is not just technology. It is a process, a policy, and a culture. Our...

  • 5 May 2005
  • Leslie VanCura

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.