...importantly, a thorough root cause analysis of minor incidents and near misses. Unfortunately, the aftermath of a securityincident tends to focus on short term fixes and personal accountability. This is counter-productive. Many banks and government...
http://www.computerweekly.com/blogs/david_lacey/2009/02/back_to_basics.html
...still massive benefits to be gained from well designed security awareness initiatives. I've seen huge drops in securityincident levels through smart educational projects. The problem is that this is not a subject that amateurs can easily...
http://www.computerweekly.com/blogs/david_lacey/2009/03/yes_we_can.html