Information security?
In many organisations the word “Information” tends to be given equal focus to the word “Security” when it comes to implementing ISMS policies and procedures. This, to me, is a mistake – it can lead to loss of focus on why we need to have robust controls in place, which is to protect real people.
It is very easy to lose sight of the human element of information security, all too often it is mired in the abstract of policies, procedures, remote threats and other concepts that make it difficult for individuals to relate to. As a result, there is little engagement and understanding, resulting in information security procedures being seen, at best, as tick box exercises and, at worst, as blockers to achieving objectives.
However, humans are a key element in all aspects of information security. As customers and/or users, the information held has value and there could be a real world impact to them if compromised. Of course, the same is true of employee information held in any organisation, and then there is the potential effect on jobs should a significant breach occur.
Understanding the potential harm to people in the event of a breach brings a sense of priority to information security measures. These vary from company to company and so, this blog is going to focus on the 2nd aspect;
As employees, humans are the best asset at a company’s disposal for ensuring a solid security posture. Conversely, they can be one of the biggest risks. So a well informed and motivated team is the best defense you can have in ensuring a strong information security posture, whilst significantly reducing the risk employees can present. Therefore, consultation and training are vital parts of any strategy.
It’s good to talk!
Through consulting with the teams that will be living with policies and procedures, we learn what their motivations and challenges are and how they currently approach the work and what processes are in place. These details are vital in designing controls that complement existing workflows and objectives. This will help increase the buy-in and adoption. It becomes understood that information security isn’t there to slow down or complicate issues, but instead to assist colleagues in achieving their goals whilst protecting people from potential harm. Coupled with effective training, this is a recipe for success!
The information and understanding gained through consultations should be fed back into the training sessions, allowing for risks to be directly linked to activity and examples of why information security matters.
Real world risks
Linking risks to the potential harm to customers or colleagues, and the processes actually in use is a remarkably effective way showing the real world impacts of poor information security implementation and control. When people realise the effect a breach could have on their customers and colleagues it becomes a significantly more personal matter, demanding more of their engagement and effort.
Presenting relevant threats in training is key, A lot of information security training talks about state sponsored espionage, terrorist organisations and other global level threats. This can come across like the plot of a Hollywood movie and bears little to no resemblance to the threats facing most companies (of course, it is relevant to some businesses, in which case – crack on!). In the majority of cases, a disgruntled employee, or someone not knowing the correct process, or a phishing email are larger and much more realistic risks to talk about.
Individual benefits
An element often overlooked is a lot of information security training can benefit employees in their personal lives as well as protect the company. With this in mind, it is a great idea to emphasis this when delivering training on appropriate subjects as this will help engage the team. For example, knowing what a phishing email looks like will help protect personal assets as well as company. Safety tips for working in public places (wifi hotspots, etc) isn’t only going to help the business.
Including information tailored towards individual benefit when delivering training will help colleagues see the information security team as a source of helpful, useful information. This will foster a much more positive attitude towards the subject and, as a result a greater inclination to ask questions, query concerns and jump on board the information security journey.
Starting the journey
Training should commence from day 1 of an individual’s journey with the company. We must recognise that everyone will have different experiences and impressions of information security. Everyone should be trained in what information security means within your organisation; how it is defined, how it is implemented, and how important it is.
Introductory training should be concerned with “base lining” the knowledge and ensuring everyone has the same basic understanding regardless of background, rather than diving deeply into specialist areas – this sort of training can be delivered to colleagues at the appropriate time and as required to assist them in fulfilling their role and duties.
Human security?!
Whichever way you look at it, humans are at the heart of information security. Policies, processes, and technology are simply the ways that we protect some groups of individuals and enable others to work. Keeping this in focus will definitely improve your information security posture…. or should that be human security posture?!
