« Security is the Foundation of Internet Governance | Main | The Old Ones Are the Best »

Human Factors Dominate Today’s Security Problem Space

Earlier this week I gave the closing keynote address at Kable’s Information Security in the Public Sector conference in London. The subject, requested by Kable, was “Creating a Security Conscious Culture”. It’s another indication of the growing importance of human factors in today’s security and IT problem space. And it’s not just in user education. The key obstacles and enablers to aligning security with business goals, or in joining up Government IT, are politics, perception and relationship management.

A year or two ago there was much less interest in human factors. Today it’s the most requested topic for advice, research or presentations. The UK Technology Programme is investing millions of pounds in research in this area. Leading universities are building more human factors content into their courses. And sales of security education services are at an all time high. I’m already booked to give presentations on the subject next year in UK and USA.

Will this trend continue? Yes, it has a long way to go. The major obstacle at present is the shortfall of budget and resources assigned to the subject. It can take years for such vital enablers to catch up with the latest challenges. But there is a compelling business case because it reduces incidents and, more importantly, their associated costs. If your organisation is not spending at least 10% of its security budget on security awareness and behaviour change, then it's probably got the balance wrong.

TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/14848

Comments (1)

Andrew Yeomans:

See today's Dilbert cartoon http://www.dilbert.com/comics/dilbert/archive/images/dilbert2007113333116.gif on security and usability.

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on November 15, 2007 11:09 AM.

The previous post in this blog was Security is the Foundation of Internet Governance.

The next post in this blog is The Old Ones Are the Best .

Many more can be found on the main index page or by looking through the archives.