Home > Creating a security awareness culture
Royal Holloway eBook Series:
EMAIL THIS

Creating a security awareness culture

21 Jun 2009

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Well trained users can be one of the best defences against security breaches. But instilling good security practices among computer users who have other higher priorities – such as their main job – is often difficult to achieve.

A new article published in SearchSecurity.co.uk argues that many security awareness programmes fail because they rely on a top-down approach, telling users what they cannot do, rather than encouraging them to behave in a responsible way.

More from Royal Holloway

Have a look at the rest of the 2009 theses from MSc graduates of Royal Holloway, University of London (RHUL).
The article, written by Carlos Orozco Corona and John Austen (see below for .pdf), is part of our 2009 series featuring the best new MSc theses from graduates of the information security group at Royal Holloway University of London (RHUL).

Entitled 'Social and Behavioural Techniques to Boost Awareness' (see below for full .pdf), the article argues for a much more inclusive and co-operative approach to the development of awareness programmes.

Drawing heavily on research into social interaction and behaviour, the authors suggest that awareness programmes work best by first identifying those individuals within departments who are the main opinion leaders and best communicators.

Any new awareness campaign is then directed initially just at those people, who can be relied upon to discuss it with their colleagues and generally lay the foundations for a later message that goes out to all staff who, by this time, have been well primed to be more receptive.

The article provides detailed advice on how to go about an awareness campaign, and would be a useful guide for anyone charged with raising security awareness in an organisation.

Read Social and Behavioural Techniques to Boost Awareness (.pdf) by Carlos Orozco Corona and John Austen.

SearchSecurity's association with RHUL began last year when we published 12 articles from RHUL's MSc graduates. These were widely appreciated for their new ideas and relevance to security problems. We believe the 2009 series is equally wide-ranging and thought-provoking.

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Policies and User Awareness
Cloud-based services require stalwart business continuity plans
Preventing phishing attacks: Enterprise best practices
CISOs take measured steps to reduce social media risks
Increasing information security awareness in the enterprise
How to develop a culture of security in the enterprise
Creating and enforcing a clear-desk policy
Physical security threats: Don't gift your data away
Cut down on calls to help desk with cybersecurity awareness training
Layoffs prompt insider threat fears, cybersecurity survey finds
How to write an information security policy

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Financial Services Authority  (SearchSecurityUK.com)
IISP (Institute of Information Security Professionals)  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




UK Network Security: VPN, Threat Management, Endpoint Protection, Wireless Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts