Staff 'need reasons' to believe in security

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Companies must ensure that their staff understand the reasons behind security policies and support them, rather than just dictating them from on high, a government consultant said at Secure London 2005 on Tuesday.

Paul Hansford, class consultant for GCHQ and senior consultant at Insight Consulting, said that many security procedures fail because staff don't understand what their company is trying to do.

"It is not enough to get staff to literally 'sign up' to procedures — they must fully appreciate their purpose," he said.

He recalled an apocryphal story illustrating the point: "A colleague went into a government agency and at one cluster of desks saw a line of 'bobbing bird' toys. The system locked out the user if they didn't touch the keyboard for a certain length of time, and required them to re-input their password. The 'bobbing birds' were lined up next to everyone's computer so that they would tap the 'enter' key every 30 seconds."

The underlying beliefs of staff can be at odds with security policy, he said. "People tend to have a 'What's in it for me?' attitude. For example, some people may feel that it's fine to share passwords if it makes the business tick over, their attitude being that business is more important than security," Hansford said.

"Companies need to assess people's security training needs, which includes having to elicit how security 'aware' they are," he said. "Awareness is not just about education and training, but is also an appreciation of, and a motivation to support, an issue."

An IBM security expert emphasised the need to monitor personnel to maintain security levels.

"Personnel security is not just about initially screening and vetting employees, but it's also about monitoring the guy who might have personal problems," said Julian Lander, IT security programme manager with IBM. "If their work performance isn't right, they may be involved in drug or alcohol abuse, or if they have an overelaborate lifestyle — which I've seen in the past — that can indicate possible security problems."

Lander argued that security procedures need to recognise the human factor. "Security is about people. Speaking generally, the way to address the problem is by coaching, mentoring or counselling — all the soft skills that HR has. You have to work with HR to maintain a successful security policy," Lander said.

According to Hansford, security standards become harder to maintain as more staff work remotely - noting that more than half of all UK businesses currently allow staff remote access.

"As more staff work remotely, physical security is difficult to achieve. At the end of the day (employers and security professionals) won't be there, so procedural security needs to be got right," he said.

Talkback

This line; "An IBM security expert emphasized the need to monitor personnel to maintain security levels." is a big joke. IBM remote users connect to their VPN with a single password sign on. IBM does not monitor anything or anyone. One of these days you folks are going to wise up and find out IBM can't find their butt. Security is something IBM can't spell. All companies rely on the user to be accountable for their actions. Until Security developers and companies remove the burden of securing documents from users we are going to have security comprised. Larry Ellison said it best; "To reduce security breaches, businesses should encrypt their databases." He missed it slightly, as he always does. Those intinities that require security should encrypt all their documents. Why don't they? Its too darn difficult. You've got to make it easy for the user, if you don't, it ain't gona happen. One company I know has, they used the KISS (Keep it Simple STUPID) theory. Email me I will tell you the name of the company.

via Facebook 14 October, 2005 01:32
Reply

The problem is that what gets selled (or purchased) usually isn't that what works security wise. Because those that purchase or decide usually can't be really bothered with security (it's not what they get tapped on the fingers for if they get it wrong).

So perhaps security experts need to get a grip on the (internal) purchasing and decision making processes first.

After all , security is also about keeping bad things out and getting good things in.

via Facebook 17 October, 2005 22:27
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

2 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

3 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

3 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

3 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

5 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

6 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

12 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

14 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

14 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

16 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

16 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

17 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

18 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

18 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

18 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

19 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

19 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

19 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

19 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

22 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA