It's time again to celebrate that wonderful US event... Happy Cyber Security Awareness month! This partnership between Homeland Security, NCSA (National Cyber Security Alliance) and the MS-ISAC (Multi-State Information Sharing and Analysis Center) is an opportunity to recognize the importance of information security. It started in 2003 as a way to build awareness for online security and privacy and to encourage individuals, business and government.
This month I'll be putting out weekly posts connected with the weekly themes put together by DHS. This week the theme is creating a culture of security.
The message is simple... in the workplace security is a team sport. All organizations have customers, patients, systems and data to protect. To accomplish this, security must be part of everyone's job.
A place to talk about information security, Internet safety and, of course... coffee!
Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
Showing posts with label policies. Show all posts
Showing posts with label policies. Show all posts
Monday, October 5, 2015
Tuesday, May 13, 2014
The Best (First Good) Password Policy Ever!

- good passwords are hard to remember, and;
- passwords you can remember are easy for attackers to guess.
- 8 characters;
- upper/lower case;
- numbers;
- special characters.
Labels:
access,
account,
ArsTechnica,
basics,
controls,
encryption,
infosec,
login,
master password,
password,
passwords,
policies,
policy,
practices,
vault
Tuesday, February 11, 2014
Bad Policies = Bad Passwords
- good passwords are hard to remember, and;
- passwords you can remember are easy for attackers to guess.
Many organizations allow you to pick poor passwords on their websites by enforcing few or weak password construction requirements.We call these password policies, and these specify things like: how long the password can be; the minimum length it must be; what kinds of characters can or must be used; if the password needs to change, and; if there are some passwords that can't be chosen.
Tuesday, April 16, 2013
Bring It On Home
There have been a number of discussions about the value of Security Awareness training floating around the net. Some say that even with training, people will still fall for phishing attacks and social engineering, and that networks and servers will still get hacked. I wrote about this a while back.
I think there is great value to awareness training. To me, the content and delivery are key considerations. If the security messages are the same old, rehashed information then it will be hard to get people to pay attention, care and retain information. No one wants to see yet another dry review of an organization's security policies.
But there is a better way...
Labels:
awareness,
computer,
consumer,
email,
home,
information,
kids,
online,
policies,
presentations,
privacy,
program,
security,
slideshare,
technology,
training
Tuesday, November 20, 2012
Stuff I Say - People Want To Do The Right Thing
In the security field we hear a lot about the insider threat. There have been plenty of well publicized incidents of internal employees, contractors or ex-employees stealing information, or deleting information or leaving some other kind of destruction before they leave an organization I'll cover this topic in more detail in a future post.
While this certainly does happen, it's not prevalent. Call me an optimist... but I think that people generally want to do the right thing.
And this is where the problems begin. Sometimes those who make the rules and enforce the rules just make it too difficult to do the right thing!
While this certainly does happen, it's not prevalent. Call me an optimist... but I think that people generally want to do the right thing.
And this is where the problems begin. Sometimes those who make the rules and enforce the rules just make it too difficult to do the right thing!
Labels:
awareness,
basics,
compliance,
controls,
enterprise,
ethics,
information,
insider,
IT,
policies,
policy,
security,
threat
Tuesday, November 13, 2012
Stuff I Say - You Pay by the Word
This is a continuation of a series of posts on some of my philosophies about security strategy. These ideas are covered in a fun talk entitled #*%! My CISO Says, covering a range of security governance and management topics. Slides are on my slideshare page. The first two posts are here and here.
In that second post I was talking about policy. Traditionally many organzations have staff sign a form that says that they have read and understood policy. Perhaps the organization has some kind of new employee orientation at which policy is reviewed. Among the problems is that policy is usually too long and too complicated. It then becomes a TL;DR document (Too Long; Didn't Read). I'm sure that both policy writers and policy readers/recipients can relate to this.
So what to do? I like to say that "you pay by the word", because you can pay now or pay later...
In that second post I was talking about policy. Traditionally many organzations have staff sign a form that says that they have read and understood policy. Perhaps the organization has some kind of new employee orientation at which policy is reviewed. Among the problems is that policy is usually too long and too complicated. It then becomes a TL;DR document (Too Long; Didn't Read). I'm sure that both policy writers and policy readers/recipients can relate to this.
So what to do? I like to say that "you pay by the word", because you can pay now or pay later...
Tuesday, October 2, 2012
Stuff I Say - No One Has Ever "Read and Understood"
Most organizations have policies. Most medium-to-large sized organizations have security policies. I hope that yours does! Policies are a cornerstone to a security program. People need to know what to do and policy is that high-level guidance.
Of course, people need to read those policies!
Many organizations will have staff sign a form that states they have read and understood the policies. Sometimes this happens just once. Sometimes it's annually, perhaps at the same time as an annual performance review. Sometimes it's when a person joins the organization, or shortly thereafter.
But does that work? What is the goal? I say that doesn't work! No one has ever "read and understood"!
Of course, people need to read those policies!
Many organizations will have staff sign a form that states they have read and understood the policies. Sometimes this happens just once. Sometimes it's annually, perhaps at the same time as an annual performance review. Sometimes it's when a person joins the organization, or shortly thereafter.
But does that work? What is the goal? I say that doesn't work! No one has ever "read and understood"!
Labels:
basics,
business,
compliance,
controls,
enterprise,
management,
policies,
policy,
security,
sign-off,
signature,
staff,
technology
Subscribe to:
Posts (Atom)
