+ All Categories
Home > Documents > Three C’s of Security Awareness: Culture, Change and Creativity

Three C’s of Security Awareness: Culture, Change and Creativity

Date post: 07-Jan-2016
Category:
Upload: allan
View: 28 times
Download: 1 times
Share this document with a friend
Description:
Three C’s of Security Awareness: Culture, Change and Creativity. Chief Information Security Officer. Barbara McCrary. The Three C’s of Security. Culture Change Creativity. Culture, change, and creativity are central to protecting an organization’s data and assets. Culture. - PowerPoint PPT Presentation
Popular Tags:
14
Barbara McCrary Chief Information Security Officer Three C’s of Security Awareness: Culture, Change and Creativity
Transcript
Page 1: Three C’s of  Security Awareness: Culture, Change and Creativity

Barbara McCraryChief Information Security

Officer

Three C’s of Security Awareness:Culture, Change and Creativity

Page 2: Three C’s of  Security Awareness: Culture, Change and Creativity

• Culture • Change • Creativity

The Three C’s of Security

Culture, change, and creativity are central to protecting an organization’s data and assets.

Page 3: Three C’s of  Security Awareness: Culture, Change and Creativity

• A Company’s Way of Life – Behavior and Practice– Standards– Habits and Routines– Traditions

Culture

Page 4: Three C’s of  Security Awareness: Culture, Change and Creativity

Behavior and Practices

– Organization Silos– Communication– Productivity– Environment

Page 5: Three C’s of  Security Awareness: Culture, Change and Creativity

Change IT’s Ideas About Effectual Security

• Update Standards• Habits and Routines– Process pertinent data first– Simplify

• Automate Traditional Processes

Page 6: Three C’s of  Security Awareness: Culture, Change and Creativity

To improve security and security awareness:

Change!

Change

Page 7: Three C’s of  Security Awareness: Culture, Change and Creativity

Keys to Change

• Protecting data is a shared responsibility.

• Encourage active participation from all stakeholders.

Page 8: Three C’s of  Security Awareness: Culture, Change and Creativity

Change Everyone’s Idea of Security Awareness

Training• Regular, daily, weekly, monthly

campaigns that look more like conversations than training.– Focused and Small Bites– Reinforce– Applicable

Page 9: Three C’s of  Security Awareness: Culture, Change and Creativity

Change Everyone’s Idea of Normal

• Inspire thought and conversation about ethical computing.– Change unethical norms. – Redesign decision processes.– Reinforce organizational ethics

using reminders and currently held communication tools.

Page 10: Three C’s of  Security Awareness: Culture, Change and Creativity

What can we really do to encourage ethical and secure corporate behavior?

Get Creative!

Creativity

Page 11: Three C’s of  Security Awareness: Culture, Change and Creativity

Incorporate a Variety of Awareness Tools

• Add security to process training.• Send info on trending and current

events.• Include info that applies to

personal lives, families and personal finance.

Page 12: Three C’s of  Security Awareness: Culture, Change and Creativity

Designing Security Awareness Materials

• Consider the differences:– generations– gender – seniority

Page 13: Three C’s of  Security Awareness: Culture, Change and Creativity

Summing It Up

To quote ― St. Francis of Assisi

“Start by doing what is necessary, then what is possible, and suddenly you are doing the impossible.”

Page 14: Three C’s of  Security Awareness: Culture, Change and Creativity

QUESTIONS?


Recommended