Making Security Awareness Happen

نویسنده

  • Susan D. Hansche
چکیده

INTRODUCTION This article focuses on the first step of providing computer and information system security — developing and implementing an effective security awareness program. One might wonder why security awareness is not considered the same as training. The simple answer: because the desired outcome of each is different. The goal of a security awareness program is to heighten the importance of information systems security and the possible negative effects of a security breach or failure. During an awareness campaign, the end user simply receives information. It is designed to reach a broad audience using various promotional techniques. In a training environment, the student is expected to be an active participant in the process of acquiring new insights, knowledge, and skills. When designing and developing an information technology (IT) security training program, there is a wide range of options that are based on specific job requirements and the daily management, operation, and protection of information systems. IT is apparent in every aspect of our daily life — so much so that in many instances, it seems completely natural. Can you imagine conducting business without e-mail or voice mail? How about hand-writing a report that is later typed using an electric typewriter? As one is well aware, computer technology and open-connected networks are the core comP A Y O F F I D E A

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

I Am Fine but You Are Not: Optimistic Bias and Illusion of Control on Information Security

Information security is a critically important issue in current networked business and work environments. While there is extensive publicity on the increasing incidents of numerous information security breaches and their serious consequences, recent surveys and research on information security repeatedly identify the low levels of user and managerial awareness as a key obstacle to achieving a g...

متن کامل

Aligning Security Awareness With Information Systems Security Management

This paper explores the way information security awareness connects to the overall information security management framework it serves. To date, the formulation of security awareness initiatives has tended to ignore the important relationship with the overall security management context, and vice versa. In this paper we show that the two processes can be aligned so as to ensure that awareness a...

متن کامل

The Need for Effective Information Security Awareness

Security awareness is an often-overlooked factor in an information security program. While organizations expand their use of advanced security technology and continuously train their security professionals, very little is used to increase the security awareness among the normal users, making them the weakest link in any organization. As a result, today, organized cyber criminals are putting sig...

متن کامل

Value-focused assessment of ICT security awareness in an academic environment

Security awareness is important to reduce human error, theft, fraud, and misuse of computer assets. A strong ICT security culture cannot develop and grow in a company without awareness programmes. This paper focuses on ICT security awareness and how to identify key areas of concern to address in ICT security awareness programmes by making use of the value-focused approach. The result of this ap...

متن کامل

Value-Focused Assessment of Information Communication and Technology Security Awareness in an Academic Environment

The aim of this paper is to introduce the approach of value-focused thinking when identifying information and communications technology (ICT) security awareness aspects. Security awareness is important to reduce human error, theft, fraud, and misuse of computer assets. A strong ICT security culture cannot develop and grow in a company without awareness programmes. How can personnel follow the r...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007