Culture of Security

November 11, 2007, 07:21 PM —  ITworld.com — 

Listen to the column Culture of Security, or visit our Podcast Center to hear more by James Gaskin.

During the Altiris ManageFusion conference in October, I had the
pleasure of being on a security "panel of experts" for infotainment
during lunch one day. A panelist I hadn't met, Andi Mann
of EMA, used
a wonderful phrase I warned him I would steal: culture of security.

Mann's point, and I think it's a great one, is that manufacturing
companies don't warn you about every single danger on the shop floor,
but they use OSHA regulations and employee training to create the
"culture of safety." Employees don't need to be told directly not
to

stick their hands into a band saw because that falls under the culture
of safety training.

Imagine if your users understood the culture of security as well as they
understand not to stick forks into AC sockets. Wouldn't life be better
for IT and the general user population?

Now the question becomes how you instill a culture of security in your
business. After all, employees are adults with decades of safety
training, yet some still stick their forks into AC sockets.

This culture must drift down from above. Not the heavens, but executive
row (some of them may think they're angels in heaven, but we know
better). Training executives requires a considerably lighter touch, and
more patience, than training regular employees. But train them you must,
because many idiot vice presidents remain the biggest security holes in
major companies.

One mainframe data processing manager I met years ago enforced his
culture of security with a hammer. When he went to a new location, the
first data systems operator who walked away from a terminal without
locking said terminal got hit with said hammer. Actually the employee
got hit with a giant pink slip, so it was a metaphorical hammer. After
the first termination, remaining employees took security much more
seriously.

While a hammer for an executive training tool sounds wonderful, it's not
legal. So use something scarier than hammers: lawyers. SOX and HIPAA and
other government mandated regulations should make a culture of security
easier to establish than ever before. Audit trails live forever, and
stupid e-mail messages never die. Data lost in a company laptop or PDA
always make headlines.

Executives get leader salaries, and they must lead for security to be
taken seriously. Time for some culture in executive row, a culture of
security.

Andi Mann: http://emausa.com/web/ema_bio_mann.php

ITworld.com

Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
peer-to-peer

jfruh
Apple syncing patent can't come soon enough

pasmith
New Twitter features borrow from 3rd party clients

Esther Schindler
Open Source Changes the Software Acquisition Process

mikelgan
How to set up continuous podcast play on the new iTunes

David Strom
Five important Windows 7 mobility features

sjvn
Guard your Wi-Fi for your own sake                        

Sandra Henry-Stocker
Grepping on Whole Words

 

Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325

Join the conversation here

The Daily Tip

The Daily TipQuick, practical advice for IT pros. Made fresh daily.

Hot tips:

Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.

Newsletters

Subscribe to ITWORLD TODAY and receive the latest IT news and analysis.

I would like to receive offers via email from ITworld partners.
By clicking submit you agree to the terms and conditions outlined in ITworld's privacy policy.
Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace