Building a security culture

Building a security culture
Building a security culture
Lately there has been a lot of discussion about the difference between real security and compliance with data security regulations. I think we can all agree that security, like life, is a journey, not a destination, and regulatory compliance can get us only so far. True security requires a combination of people, processes and technology.

People are often the most overlooked element in any security strategy. This is unfortunate, because no matter how solid the technology and the processes, if the people are not engaged, data breaches happen.

One of the more positive steps an enterprise can make is to institute ongoing security awareness training for all employees, whether it's a cashier or customer service rep. But don't just present the material and hope for the best. Follow any employee training with testing to gauge understanding and to reinforce the vital importance of security.

Among other data-driven security processes, an enterprise security policy must clearly state how people should respond to requests for sensitive information. This security policy should be enforced by technology controls, so employees can't be coerced into providing hackers with information, and also to reinforce the importance of security within the enterprise.

A strong culture of security will emphasize the fact that each employee is a valued participant in preventing data breaches, not a child who is being monitored. It takes time to build an internal corporate culture, and it takes reinforcement to drive home a security message, but to make progress on the security journey, we need to bring all employees in the company along with us.
close

Next Article in Opinions

More in Opinions

Follow me on this, your security team includes non-security people

Follow me on this, your security team includes ...

A successful security professional will tap into an organization's entire employee base to get results. And the benefits will go both ways.

Me and my job: Marty Edwards, ICS-CERT

Me and my job: Marty Edwards, ICS-CERT

Marty Edwards' job is to coordinate efforts between the government and the private sector.

Debate: Is advanced malware no longer a problem when administrator rights are ...

In this month's debate, experts discuss if advanced malware is still a persistent challenge after administrator rights are removed.