Home    Forums    Feature Requests    Beta Issues    SysAid Resources    Documentation    Support
Hello Guest,  Login   
        
DOWNLOAD FREE EDITION
    
     Recent Topics    Hottest Topics    Online Members    Member Listing    Advanced Search
IT security training - a help or a push ?  XML
Forum Index » General IT Discussions
 
Author Message
Obelix
SysAid Wiz


SysAider from release 3.1 Indonesia Pathfinder
Joined: 12/06/2008
Messages: 901
Offline

Educating users has been suggested for years as a best practice in network security. It makes a lot of sense especially now when, thanks to the advance in perimeter security technology on server side, the threat shift from the system to the application hence the new branch - endpoint security. So it's the first thing that come to my mind when I got overwhelmed by the work I need to do just to keep up.

The thing is everytime I sweep the faces of my users... how they sneered triumphantly cause they managed to sneak in some porn or multimedia files... or seriously chatting... or sigh upon another facebook hunks... I just...
I can't help to think the education will be more a push than a help.

What I'm talking about is... in security... you can't talk about the protection without mentioning the attacks. Now what guarantee after the training the users will exercise more of the protection than the attack ? Would they be awaken and start doing things cautiously... or would they be "enlighted" and start creatively pushing the boundaries ?

I know... I know... security through obscurity doesn't work. They eventually will learn it somewhere anyway. All eyes upon the subject is better than SOME eyes. Have faith on people. Be positive. But in risk management don't we have the responsibility to minimize the risk ?

So should we or should we not educate ?

That is not a bug, it's a feature...
When everything else fail try SysAid Wiki by Techguy
scumgrief
Super SysAider

SysAider from release 5.6 United States Pathfinder
Joined: 25/02/2009
Messages: 57
Offline

For our organization (dealing with medical records) we decided to actively discipline staff (getting Human Resources involved) who were caught with a security violation. But it hardly seemed fair to discipline staff for something they didn't receive training on. So we have a very thorough, required annual security training, with the understanding that if staff violate the security policies they are being trained on, there will be consequences (oral warning->written warning->termination, etc)

So I would say, if you decide to do security training, you have to be ready to take a stand and have a process in place to enforce your policies/rules.

But if you don't train, it's pretty hard to enforce your policies.

scum
avc
SysAider

SysAider from release 5.5 United States
Joined: 03/07/2008
Messages: 9
Location: Atlanta, GA USA
Offline

being at a small shop, I found this video and gave it to the training dept to show people:

http://www.vita.virginia.gov/communications/publications/servicebulletin/default.aspx?id=7456&QuarterImage=second08

4th item down "New video: "The Duhs of Security" promotes effective security"


you can also find it on youtube.

Obelix
SysAid Wiz


SysAider from release 3.1 Indonesia Pathfinder
Joined: 12/06/2008
Messages: 901
Offline

This is true story and fresh from my cave...

I fire a mass e-mail warning user that powerpoint is now the fav target. You know what's the first and most asked question ?

"How do they put the malware in powerpoint ?"


That is not a bug, it's a feature...
When everything else fail try SysAid Wiki by Techguy
Tim Sutton
Super SysAider

SysAider from release 2.5 United Kingdom
Joined: 15/07/2008
Messages: 59
Offline

Obelix wrote:This is true story and fresh from my cave...

I fire a mass e-mail warning user that powerpoint is now the fav target. You know what's the first and most asked question ?

"How do they put the malware in powerpoint ?"

My reply would be "it's very complicated but we are seeing active use of this in the wild and as such you need to be aware of it"

There's a difference between making people aware that things are dangerous and showing them how to do "black hat" stuff.

If you want some good reading on security which isn't dry at all, try Security Monkey's blog over at ITToolBox.com. http://blogs.ittoolbox.com/security/investigator/ Have a read of his case files as they set real security into a realistic scenario ... plus they fun to read.
Forum Index » General IT Discussions
Go to:   
Help Desk Software
Free Help Desk Software
Free Asset Management Software
SysAid Helpdesk Software
Web Based Help Desk Software
SysAid Help Desk Forum
General IT Discussion Forum
SysAid CSS Customer Service Software
Customer Support Software
   SysAid Technologies Ltd.
   Toll-Free phone center (U.S.): 1-800-686-7047
   Offices - U.S.617-231-0124
   Israel:+972-3-533-3675
   Skype account:ilient
   Email:helpdesk@sysaid.com
   Optimized by SEO Israel
   SysAid logos and other SysAid Technologies marks
   are trademarks or registered trademarks of
   SysAid Technologies Ltd.
   All Rights Reserved by SysAid Technologies Ltd.
   2002-2011
   Live Support Hours
   07:00 AM - 09:30 PM (UK)
   02:00 AM - 04:30 PM (EDT)

   We provide worldwide services, and we do our best
   to match the working times of customers from
   different time zones.

   SysAid Help Desk Software and Asset Management Software
Privacy Policy © Terms Of Use