Log In   |  Register Free Newsletter Subscription
Skip navigation
Zibb
Subscribe to Control Engineering
FirstLight
RSS
Email
Average Rating:
  • (1)
    Rate this:
  • Security Awareness – Changing the Behavior of Your Workforce

    December 16, 2008

    After closely reviewing the entire set of NERC CIP standards and their 45 supporting requirements, it is easy to notice their dominating technical security undertones.  The NERC CIP standards have a very strong emphasis on cyber critical assets, electronic security perimeters, event management / situational awareness, and identity and access management, just to name a few.  However, there is one core non-technically oriented standard – NERC CIP-004-1 – which, among other things related to personnel, focuses on security awareness and training (R1 and R2). 

    When reflecting upon the security of your organization, security is comprised of technical, physical, and administrative safeguards.  Examples of technical safeguards / controls include those I previously mentioned, but in greater detail, firewalls, malicious software prevention technologies, and event monitoring and notification capabilities.  Physical safeguards focus on the security of facilities and equipment, such as video surveillance, biometric access control technologies, and reception areas and escorting practices.  Finally, administrative safeguards focus on concerns including workforce security, incident management, security awareness, and business continuity planning and disaster recovery. 

    In the context of non-technical security safeguards, the question becomes, “What is among the most effective ways in which an organization can enhance its security posture?”  The answer is security awareness when the focus of security awareness is to enact behavioral change among the entire workforce.  That is, security awareness should focus on changing workforce behavior by reinforcing acceptable security business practices; you do not want the business practices of the workforce to introduce undesirable risk to your organization. 

    You may have noticed repetitive mentioning of the word “behavior.”  Why is the behavior of your workforce so important?  Consider the following:

    • A <choose role here> is entering a control center and holds the door open for someone nearby, even though the <choose role here> does not recognize the person.
    • A <choose role here> has completed the use of ESP architecture diagrams and wads them up into a ball and disposes of them in the trash can (i.e., vs. shredding the architecture documents.)
    • A <choose role here> uses the same password for all network and application access, which consists of the combination of the first names of his two pet dogs – “StanJake”.
    • A security guard at the main reception area leading into a generation plant engages in good conversation with a visitor and allows the visitor unescorted access into the generation plant.
    • A <choose role here> clicks on an email attachment from someone he does not recognize simply due to curiosity regarding the contents of the attachment.

    These are just a few examples of behaviors any organization would want to prevent due to the potentially severe security risks they would pose. 

    Rather than focusing your security awareness strategy on simply imparting subject matter applicable to your entire workforce under the auspices of being informational, your security awareness strategy should focus on transforming your workforce’s behavior to the specific behavior you have assessed will yield the minimal (if any) amount of risk to your organization.

     

     

     


    www.encari.com

    Posted by Matthew Luallen & Steve Hamburg on December 16, 2008 | Comments (4)
    Average Rating:
  • (1)
    Rate this:

  • July 15, 2009
    In response to: Security Awareness – Changing the Behavior of Your Workforce
    Arianamums commented:

    Very nice blog. I totally agree with your thoughts.


    July 15, 2009
    In response to: Security Awareness – Changing the Behavior of Your Workforce
    Jessicahep commented:

    Great! Thank you very much! I always wanted to write in my blog something like that. Can I take part of your post to my site? Of course, I will add backlink? Regards


    December 19, 2008
    In response to: Security Awareness – Changing the Behavior of Your Workforce
    Steven Hamburg commented:

    Kulakarni - It would be helpful if you would please elaborate upon your questions. It would be helpful if you would provide context to your question involving major security control systems. Thank you, Steve.


    December 17, 2008
    In response to: Security Awareness – Changing the Behavior of Your Workforce
    kulakarni commented:

    What are the major security control systems?

    POST A COMMENT
    Display Name
    captcha

    Before submitting this form, please type the characters displayed above. Note the letters are case sensitive:

    Advertisement
    AIG2010_160x160
    Advertisement
    2010Sensors160x160
    NEWSLETTERS
    Weekly News
    Process Instrumentation & Sensors Monthly
    System Integration Monthly
    Process & Advanced Control Monthly
    Machine Control Monthly
    Information Control Monthly
    Product Review
    Sustainable Engineering
    Simplified Safety
    Fieldbus Facts
    PROFInews North American Edition



    Please read our Privacy Policy

    About Us   |   Advertising Info   |   Site Map   |   Contact Us   |   FREE Subscription   |   Useful Sites   |   RSS
    © 2010 Reed Business Information, a division of Reed Elsevier Inc. All rights reserved.
    Use of this Web site is subject to its Terms of Use | Privacy Policy