Story: IT departments being passed the security buck
We agree with the point being made but the emphasis should not be on the IT, HR or even the legal department – it needs to be on the board members of an organisation. It is imperative that the board understands the importance of the issues concerning IT security and make it clear that they support and adhere to the IT policies that are in place.
Policies, and the procedures that underpin them, are the only way to ensure that employees know where they stand and what is expected of them. Unless you state and communicate effectively what is acceptable use of IT, employees will not know they are doing anything wrong. If that communication comes from the top then there is no excuse for employee unawareness.
Full Talkback thread

