unix and linux operating commands

The true meaning of "security awareness training"

 
Thread Tools Search this Thread
# 1  
Old 12-10-2010
The true meaning of "security awareness training"

My eye has been caught once again this afternoon by yet another advertisement disguised as a press release breathlessly informing us that the company can deliver "security awareness training".  It seems innocuous enough, but what does this three-word phrase really tell us about them?

Let me explain.  I consider myself an information security awareness professional - that is, I help customers improve their employee's awareness of information security matters.  Awareness, in my book at least, is a generalized approach, spreading the good word about information security and so leading to a broad company-wide understanding of information security, along with the motivation for employees to behave more securely and help protect valuable yet vulnerable information assets.  My aim is very much to establish a widespread but deep-rooted security culture among the workforce, leading to information security being just "the way we do things around here".  To be truly effective, the default corporate behavior (even when the boss is looking the other way) has to be security-minded, almost instinctive.  I'm not talking about making everyone paranoid security freaks, but something far more subtle: a genuine appreciation of the true worth of information security (both to their employer and to them personally), along with sufficient useful, practical knowledge about typical everyday information security risks and how to deal with them. 

To achieve cultural change on this scale takes patience and persistance.  For all sorts of reasons, it's not something one can achieve overnight, and the moment we stop pushing, the level of awareness starts to decay naturally.  It needs to be delivered continually, barely peeping above the parapet.  Furthermore, it takes skill to draw out the essential and meaningful security messages from the great morass of information security issues we all face, and to present actionable suggestions.  The real creativity comes not in raising awareness of the basics such as viruses and spam but in confidently tackling more important but narrower and often deadly dull security topics in a way that also brings them to life and makes them resonate with the audience.  I challenge anyone to inject some zest into awareness topics such as securing industrial control systems or business continuity planning, no matter how important these issues are. 

To me, training is something quite different.  It's what we do to performing seals - well OK maybe that's a bit harsh but the fact is that it's a decidedly different method with quite distinct aims to awareness.  For a start, training courses usually take place in discrete episodes either in dedicated or temporary training facilities or, these days, through Computer Based Training systems.  Either way, students have to set time aside from their working routines to attend - and I use that specific word advisedly.  "Attend" means they are physically present, and maybe afterwards they collect a tritle little certificate of attendance establishing that they were there.  They didn't necessarily participate or learn, mind you, nor even enjoy the experience.  Truly talented passionate trainers or teachers delivering well-designed and constructed training courses can achieve great things, but clearly they are not all in the same league.  From what I've seen of them, some CBT course providers evidently make a living turning out mind-numbingly dull voiceovers on crude PowerPoint or Flash graphics, maybe interspersed with some amateurish video footage or even worse childish games and cartoons as if they are teaching pre-schoolers to count.  The actual content of security training courses is distinctly variable in scope, quality and effectiveness, but who really cares eh, just so long as the students get their wallpaper and management can tick the "security awareness training" box? 

Finally I'd like to point out the first word in the phrase "security awareness training".  Does that mean physical security, IT security, national security, or something else?  OK, I admit I'm biased here but I consciously and deliberately use the term information security, meaning the protection of valuable information assets (including information, computer data, knowledge, experience, both proprietary and personal, plus the processes and systems used to gather, analyze, output and communicate information) against all manner of risks.  Fair enough, "security awareness" is a convenient contraction but little details like that matter to those of us who notice.

So, to sum up, companies promoting "security awareness training" raise serious doubts in my mind regarding their understanding and appreciation of the field, let alone their competence to deliver.  I wonder if they have read NIST's standard SP800-50 "Building an Information Technology Security Awareness and Training Program" or the hot-off-the-press the new second edition of Rebecca Herold's outstanding book "Managing an Information Security and Privacy Awareness and Training Program", both of which expound on the difference between awareness and training.

Caveat emptor.

Kind regards,
Gary Hinson   www.NoticeBored.com

Image
Image

More...
Login or Register to Ask a Question

Previous Thread | Next Thread

8 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

Bash script - Print an ascii file using specific font "Latin Modern Mono 12" "regular" "9"

Hello. System : opensuse leap 42.3 I have a bash script that build a text file. I would like the last command doing : print_cmd -o page-left=43 -o page-right=22 -o page-top=28 -o page-bottom=43 -o font=LatinModernMono12:regular:9 some_file.txt where : print_cmd ::= some printing... (1 Reply)
Discussion started by: jcdole
1 Replies

2. UNIX for Dummies Questions & Answers

What is the meaning of "-s" option in "if" statement?

Hi Guys, I'm sorry but I can't find answer for this, what is the meaning of -s option in "if" statement on unix scipting. Please see sample below: opath=/home/output for i in N1 N2 N3 N4 do echo $i if then grep $i $opath/N5_CRAI > $opath/N5_$i.crai chmod 777 $opath/N5_$i.crai ... (7 Replies)
Discussion started by: rymnd_12345
7 Replies

3. UNIX for Dummies Questions & Answers

Variable "##*", "% *" meaning

Hi, What means "##*", "% *" in a variable?? I have this in the script that i'm reading: ... read line echo $line echo ${line#* } echo ${line##* } echo ${line% * } ... The first print: DN: RCROOT ONRM_ROOT_MO SNW ONRM_ROOT_MO BSC BSCCC2 BTS ALTOHATILLONOR The second print:... (2 Replies)
Discussion started by: darocham
2 Replies

4. Shell Programming and Scripting

awk command to replace ";" with "|" and ""|" at diferent places in line of file

Hi, I have line in input file as below: 3G_CENTRAL;INDONESIA_(M)_TELKOMSEL;SPECIAL_WORLD_GRP_7_FA_2_TELKOMSEL My expected output for line in the file must be : "1-Radon1-cMOC_deg"|"LDIndex"|"3G_CENTRAL|INDONESIA_(M)_TELKOMSEL"|LAST|"SPECIAL_WORLD_GRP_7_FA_2_TELKOMSEL" Can someone... (7 Replies)
Discussion started by: shis100
7 Replies

5. Shell Programming and Scripting

Meaning of "b" modifier in "sort" command

I need to sort the following file by the rhdiskpower devices in the last column: Total_MB Free_MB OS_MB Name Failgroup Library Label UDID Product Redund Path 1024 851 1024 OCRVOT1_0000 OCRVOT1_0000 System UNKNOWN ... (3 Replies)
Discussion started by: wjssj
3 Replies

6. UNIX for Dummies Questions & Answers

the meaning of "!:*" in "alias foo 'command\!:*' filename"

Hi: How can I remove my own post? Thanks. (2 Replies)
Discussion started by: phil518
2 Replies

7. UNIX for Dummies Questions & Answers

Meaning of $var->{"@$row[0]"}=" "; ???

while (my $row = $sth->fetchrow_arrayref) { $var->{"@$row"}=" "; } Can anyone help me understanding above mentioned. i) As per my knowledge $row is taking ARRAY Refernce from the database ii) @$row is containing the value of 0th index of the array, testted the same. but I am not able... (0 Replies)
Discussion started by: jaigs_27
0 Replies

8. Shell Programming and Scripting

deleting newline characters but not the "true" \n character

hi, i have a file that has about 4500 rows. this was an old microsoft access databse and what i am trying to do is take out the old extra \n newline characters but not take out the "true" newline character. I will explain. i was trying to write a regular expression, but that was not... (1 Reply)
Discussion started by: caddyjoe77
1 Replies
Login or Register to Ask a Question