« The solution needs to fit the problem | Main | In search of better Identity Management »

Changing Security Culture

The recently published Poynter report on the loss of HMRC discs containing personal details of 25 million citizens confirms what most of us already suspected. Security is not taken seriously enough across many public sector organisations. It's a combination of a culture that has been allowed to grow up, as well as a failing in governance, i.e. a lack of strict targets and conformance audits to identify and correct failings.

Surprisingly there is no mention of the need for accredited certification, which is the only reliable fast-track means of enforcing security standards. The other much-needed solution is a sophisticated behaviour change programme. I say "sophisticated" to distinguish what's needed from the run-of-the-mill, half-hearted security awareness campaigns that we often see mounted in large organisations. This problem needs more serious attention, a campaign more akin to the efforts made in the nineties to eradicate crime in New York City. 

How should we go about this? Well I'm afraid you'll have to wait for my soon-to-be-published John Wiley book on managing the human factor in information security. I'm hoping it will be out early in the New Year. It will contain lots of theory, tips and practical methods for transforming security in organisations. Watch this space. 

 

Bookmark and Share


TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/29711

Comments (1)

I think that we spend far to much time trying to educate the average user, without considering that even with the best training in the world, unless you use the right technological controls, people are just going to do what they want.....

http://mark-fullbrook.squarespace.com/blog/2008/6/27/its-all-about-technology-not-people.html

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on June 26, 2008 10:43 PM.

The previous post in this blog was The solution needs to fit the problem.

The next post in this blog is In search of better Identity Management.

Many more can be found on the main index page or by looking through the archives.