The Path to Security - Preventing User Negligence Sarah Kennedy.

18
The Path to Security - Preventing User Negligence Sarah Kennedy

Transcript of The Path to Security - Preventing User Negligence Sarah Kennedy.

Page 1: The Path to Security - Preventing User Negligence Sarah Kennedy.

The Path to Security - Preventing User NegligenceSarah Kennedy

Page 2: The Path to Security - Preventing User Negligence Sarah Kennedy.

Overview

How Students are TaughtHow InfoSec Professionals

TeachWhy Awareness is ImportantGoalsTools to use

Page 3: The Path to Security - Preventing User Negligence Sarah Kennedy.

How Students are Taught

Page 4: The Path to Security - Preventing User Negligence Sarah Kennedy.

How InfoSec Professionals Teach

Page 5: The Path to Security - Preventing User Negligence Sarah Kennedy.

Let someone else handle it….

Page 6: The Path to Security - Preventing User Negligence Sarah Kennedy.

Why Awareness is Important

Symantec Study states: employee negligence and system glitches account for 64% of data breaches

62% of employees think it’s acceptable to transfer corporate data outside of the company on personal devices and cloud services

Employee negligence breaches are increasing with every study performed

Page 7: The Path to Security - Preventing User Negligence Sarah Kennedy.

Training Goals

Make it personalTrain for behavior changesCatchy

Marketing style awareness

Reinforcement and Repetition Make it fun!

Page 8: The Path to Security - Preventing User Negligence Sarah Kennedy.

This is an Ultimate Repeatable Goal!

Page 9: The Path to Security - Preventing User Negligence Sarah Kennedy.

Adam Grant - Organizational Psychologist

“Wash your hands to protect yourself”

“Wash your hands to protect your patients”

“Practice information security to protect our customers”

“Use information security to protect your family”

Page 10: The Path to Security - Preventing User Negligence Sarah Kennedy.

Negative vs Positive

“Don’t or you will be reprimanded with consequences up to termination of employment.“

Don’t let someone tailgate behind you to enter the building.

Make sure you to help prevent data breaches.

Do be mindful of people attempting to follow you into the building.

Page 11: The Path to Security - Preventing User Negligence Sarah Kennedy.

Analogies

Page 12: The Path to Security - Preventing User Negligence Sarah Kennedy.
Page 13: The Path to Security - Preventing User Negligence Sarah Kennedy.

Games!

Page 14: The Path to Security - Preventing User Negligence Sarah Kennedy.

Practicing Preventative Scenarios

Page 15: The Path to Security - Preventing User Negligence Sarah Kennedy.

Lock Your Computer Tag

Page 16: The Path to Security - Preventing User Negligence Sarah Kennedy.

Main Goals for InfoSec Professionals

Information Security is everyone’s job requirement, Not just IT’s.

To protect the customers, It’s what we expect when we are the customer.

Remember: It’s Possible!

Page 17: The Path to Security - Preventing User Negligence Sarah Kennedy.
Page 18: The Path to Security - Preventing User Negligence Sarah Kennedy.

Questions?