+ All Categories
Home > Documents > Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to...

Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to...

Date post: 27-Jul-2020
Category:
Upload: others
View: 1 times
Download: 0 times
Share this document with a friend
28
Digestible Bites of Cyber Security Awareness – Security Bytes, a Case Study Cheryl Seaman Stephanie Erickson
Transcript
Page 1: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

Digestible Bites ofCyber Security Awareness –

Security Bytes, a Case Study

Cheryl Seaman

Stephanie Erickson

Page 2: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

WHO ARE WE?

• Federal Team Lead for • Training Developer/ Policy, Awareness, and Instructional Designer at NIH Training at NIH from Triumph Enterprises

Page 3: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

     

     

OUR TALK IS ABOUT… • Ancient Times of Awareness

• Dawn of New Security Bytes • What’s a Byte and How do you make one? • Taste a Byte (of Online Identity Theft)

• Trials and Tribulations • Changes • Lessons Learned

• How Can You Do It Too

Page 4: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

WHERE DID WE COME FROM?In the Land before

Security Bytes…

Page 5: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

FROM?

WHERE DID WE COME

Page 6: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

   

WHY DO WE DO THEM?

• What do we have working against us? • What do we have going for us?

Page 7: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

         

SE•CU•RI•TY BYTES [si-kyoo r-i-tee bahyts] • 3-Prong Approach • Edutaining • Timely • Easy-to-understand • Focus on one topic

Page 8: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

         

EMAIL • Mascot • Visually appealing

• Quick read • Segmented • Easy reference

Page 9: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

VIDEO

Page 10: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

  

POSTER • Tabloid size

(11x17) • Cardstock • Enduring content

Page 11: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

  

   

HOW DO WE

• In houseMAKE• Free & subscription software THEM? • Multi-level reviews

• Section 508 Compliant

Page 12: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

   

WHO ARE THEY FOR? • Targeted to NIH users

• Videos publicly available

• Willing to share

Page 13: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

WHEN DO WE SEND THEM?

Every other month

12 1 2

3

11 10

9

Page 14: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

LET’S DIVE IN “Protecting Yourself From Identity Theft Online” Security Byte

Page 15: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

K,

SIT BACRELAX, AND ENJOY THE

SHOW

https://youtu.be/UQCzTkzIypU

Page 16: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

IMPLEMENTATION CHALLENGES • Differing email

requirements •  Lots of emails daily • Dependent on

individual ISSOs • Numerous

communications schedules

•  Inbox “Rules”

Page 17: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

ARE WE ON TARGET?

Page 18: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

LET’S DO A SURVEY

• Be careful what you ask for

Page 19: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

AWARENESS RATINGS

Emails

Videos

Posters

Page 20: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

ISSO’S EXPERIENCE

0

2

4

6

8

10

12

How Useful Are the Security Bytes to You

As the ISSO?

Not At All Useful Only a Little Useful

Neutral Useful

Very Useful

0

2

4

6

8

10

12

What is Your Senior Management’s Opinion of the Security Bytes?

No Opinion Negative

Neutral Supportive

Highly Supportive

Page 21: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

ISSO’S EXPERIENCE

0

5

10

15

20

IC Staff’s Response to Receiving Security Bytes

Staff dislike the Security Bytes and would rather not receive them

Staff have not expressed anything about the Security Bytes

Staff look forward to each new release of the Security Bytes 0 5 10 15

Yes

No

Have You Noted Any Improved Behavior

Changes Related to the Security Bytes

educational messages?

Page 22: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

METRICS ON VIDEOS “Keep up the good work. Especially, the embedded videos.” “We find the videos very helpful and we believe they help our users to better understand the subject.”

1680

10 27 1 [VALUE]hours

3193

13 64 3 [VALUE]hours0

500100015002000250030003500

TotalSecurityBytesVideoSta2s2csbyFiscalYear

FY2015 FY2016*asof3/14/2016

Page 23: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

LESSONS LEARNED

• Review Process • More ISSO Buy-In • Continually

Refining • Get Senior

Management Support

• Marketing is Key!

Page 24: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

HOW CAN YOU DO IT TOO?

Page 25: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

IDEAS FOR TOOLS/RESOURCES

Page 26: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

WAYS TO CUSTOMIZE OUR APPROACH TO YOUR ORGANIZATION

Page 27: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

AWARENESS GALLERY

• Houses previous releases of Security Bytes

• Dedicated topic pages • Other resources

Page 28: Digestble Bites of Cyber Security - NIST...ISSO’S EXPERIENCE 0 5 10 15 20 IC Staff’s Response to Receiving Security Bytes Staff dislike the Security Bytes and would rather not

THANK YOU

NIH Information Security Program

Phone: 301-881-9726 Email: [email protected] Visit us at: https://ocio.nih.gov/


Recommended