Security Awareness Starts in IT
This practical defines the current state of business operations, security design function, introduction policy development, security awareness, and communicates our new found knowledge to the IT security design team. In the LevelOne SANS Security Essentials text, Stephen Northcutt states, 'I have never ceased to be amazed by the fact that you can't take a class in information security without being told to do this or the other thing in accordance with 'your security policy'. But nobody ever explains what policy is or how to write or evaluate it'. As an industry we still are not in agreement with what effective security policy is all about. And how should it be communicated? This is one individual's attempt to provide some insight into the initial steps of delivering the security awareness message to the business starting with the IT security design function. Security awareness communications start at home 'IT to IT'. Before we deliver the 'security message' to our business users we must ensure that security management security administration and security design teams are totally aligned with our overall security policy strategy. We must understand our working frameworks roles we fulfill what 'IT security policy' is all about and its impact on the organization.
412 (PDF, 2.06MB)
10 Sep 2001Related Content
Metrics-Driven Information Security Framework as Part of Information Security Management
Research PaperThis paper presents a model of creating an actual accurate metrics-based security reporting model that is tied closely to the security management model used at the company.
- 22 Mar 2022
- Kirill Filatov
Denial of Service Deterrence
Research PaperDenial of Service has been a very useful practice for attackers and continues to remain prevalent...
- 1 Apr 2015
- Ryan Sepe
Practical El Jefe
Research PaperEl Jefe is open source process monitoring software for Windows. With this tool, incident handlers...
- 31 Mar 2015
- Charles Vedaa
Using Influence Strategies to Improve Security Awareness Programs
Research PaperEven companies with extensive, well-funded security awareness programs fall victim to attacks...
- 25 Oct 2013
- Alyssa Robinson
Talking Out Both Sides of Your Mouth: Streamlining Communication via Metaphor
Research PaperAs Security is a relatively new field, we are still learning how to communicate what we know with...
- 4 Oct 2013
- Josh More
Information Risks and Risk Management
Research PaperThis brief will cover the various exposures that companies now face as they increasingly rely on...
- 1 May 2013
- John Wurzler
Surfing the Web Anonymously - The Good and Evil of the Anonymizer
Research PaperCompanies of all sizes spend large amounts of time, resources, and money to ensure that their...
- 8 Oct 2012
- Peter Chow
Robots.txt
Research PaperAlthough this GIAC gold paper is not about search engine optimization, or SEO, this paper will...
- 31 May 2012
- Jim Lehman
A Process for Continuous Improvement Using Log Analysis
Research PaperGood security is a moving target. Walls and castles were once good defenses against attackers, but...
- 26 Oct 2011
- David Swift
Measuring Psychological Variables of Control In Information Security
Research PaperThe effects of an individual's personal feelings of control over aspects of their health have been...
- 12 Jan 2011
- Josh More
Which Disney(c) Princess are YOU?
Research PaperSocial engineering for identity theft has always been around. But now, with the advent of social...
- 18 Mar 2010
- Joshua Brower
Prelude as a Hybrid IDS Framework
Research PaperOrganizations both Large and Small are constantly looking to improve their posture on security....
- 24 Mar 2009
- Curt Yasm
The Importance of Security Awareness Training
Research PaperOne of the best ways to make sure company employees will not make costly errors in regard to...
- 14 Jan 2009
- Cindy Brodie
Vendor-Supplied Backdoor Passwords - A Continuing Vulnerability
Research PaperVendor-Supplied Backdoor Passwords - A Continuing Vulnerability
- 26 Sep 2008
- Astrid Todd
Making Security Awareness Efforts Work for You
Research PaperMaking Security Awareness Efforts Work for You
- 20 May 2008
- Rebecca Fowler
The Controlled Event Framework for Information Asset Security
Research PaperThe Controlled Event Framework for Information Asset Security
- 20 Feb 2008
- Chris Cronin
Data Leakage - Threats and Mitigation
Research PaperData Leakage - Threats and Mitigation
- 24 Oct 2007
- Peter Gordon
Identity Theft
Research PaperThe act of identity theft can be performed by anyone, it could be family, friends or spouses. The...
- 2 Jul 2007
- Ian Wolff
Social Engineering Your Employees to Information Security
Research PaperThis paper will examine the role and value of Information Security Awareness efforts in the...
- 19 Dec 2006
- Martin Manjak
Building a Security Policy Framework for a Large, Multi-national Company
Research PaperInformation Security is not just technology. It is a process, a policy, and a culture. Our...
- 5 May 2005
- Leslie VanCura
