Cargando…

Embedding security messages in existing processes: a pragmatic and effective approach to information security culture change

Companies and organizations world-wide depend more and more on IT infrastructure and operations. Computer systems store vital information and sensitive data; computing services are essential for main business processes. This high dependency comes with a number of security risks, which have to be man...

Descripción completa

Detalles Bibliográficos
Autor principal: Lopienski, Sebastian
Lenguaje:eng
Publicado: 2011
Materias:
Acceso en línea:http://cds.cern.ch/record/1399469
_version_ 1780923589803900928
author Lopienski, Sebastian
author_facet Lopienski, Sebastian
author_sort Lopienski, Sebastian
collection CERN
description Companies and organizations world-wide depend more and more on IT infrastructure and operations. Computer systems store vital information and sensitive data; computing services are essential for main business processes. This high dependency comes with a number of security risks, which have to be managed correctly on technological, organizational and human levels. Addressing the human aspects of information security often boils down just to procedures, training and awareness raising. On the other hand, employees and collaborators do not adopt security attitude and habits simply when told to do so – a real change in behaviour requires an established security culture. But how to introduce a security culture? This thesis outlines the need of developing or improving security culture, and discusses how this can be done. The proposed approach is to gradually build security knowledge and awareness, and influence behaviours. The way to achieve this is to make security communication pervasive by embedding security messages, warnings and advice in human and technological processes, and situations that already exist within an organization.
id cern-1399469
institution Organización Europea para la Investigación Nuclear
language eng
publishDate 2011
record_format invenio
spelling cern-13994692019-09-30T06:29:59Zhttp://cds.cern.ch/record/1399469engLopienski, SebastianEmbedding security messages in existing processes: a pragmatic and effective approach to information security culture changeInformation Transfer and ManagementCompanies and organizations world-wide depend more and more on IT infrastructure and operations. Computer systems store vital information and sensitive data; computing services are essential for main business processes. This high dependency comes with a number of security risks, which have to be managed correctly on technological, organizational and human levels. Addressing the human aspects of information security often boils down just to procedures, training and awareness raising. On the other hand, employees and collaborators do not adopt security attitude and habits simply when told to do so – a real change in behaviour requires an established security culture. But how to introduce a security culture? This thesis outlines the need of developing or improving security culture, and discusses how this can be done. The proposed approach is to gradually build security knowledge and awareness, and influence behaviours. The way to achieve this is to make security communication pervasive by embedding security messages, warnings and advice in human and technological processes, and situations that already exist within an organization.CERN-THESIS-2010-250oai:cds.cern.ch:13994692011-11-16T22:46:31Z
spellingShingle Information Transfer and Management
Lopienski, Sebastian
Embedding security messages in existing processes: a pragmatic and effective approach to information security culture change
title Embedding security messages in existing processes: a pragmatic and effective approach to information security culture change
title_full Embedding security messages in existing processes: a pragmatic and effective approach to information security culture change
title_fullStr Embedding security messages in existing processes: a pragmatic and effective approach to information security culture change
title_full_unstemmed Embedding security messages in existing processes: a pragmatic and effective approach to information security culture change
title_short Embedding security messages in existing processes: a pragmatic and effective approach to information security culture change
title_sort embedding security messages in existing processes: a pragmatic and effective approach to information security culture change
topic Information Transfer and Management
url http://cds.cern.ch/record/1399469
work_keys_str_mv AT lopienskisebastian embeddingsecuritymessagesinexistingprocessesapragmaticandeffectiveapproachtoinformationsecurityculturechange