14
Inclusion & Empowerment: How Participation and Awareness Influence Security Daniel J Blander, CISM,CISSP

Inclusion And Empowerment

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: Inclusion And Empowerment

Inclusion & Empowerment:

How Participation and Awareness Influence Security

Daniel J Blander, CISM,CISSP

Page 2: Inclusion And Empowerment

[ agenda ]

[ challenges ]

[ why ]

[ emerging strategies ]

Page 3: Inclusion And Empowerment

[ challenges ]

Management buy-inUser Participation

Page 4: Inclusion And Empowerment

[ challenges ]

How consistent is your security posture?Is it integrated in to your organization’s goals?

Page 5: Inclusion And Empowerment

[ challenges ]

But I have tried!

Page 6: Inclusion And Empowerment

[ why ]

Company & Stakeholder awareness of risk• “Its never happened to us before”

Stakeholder Focus: Profit, Cost, Opportunity

Page 7: Inclusion And Empowerment

[ why ]

CIO = Chief IT Officer

Security is Only for Computers

Page 8: Inclusion And Empowerment

[ why ]Self Inflicted Wounds• Techno-babble• Fear mongering – FUD & Hype

Security is a Cost Center• Security does not generate revenue

• Security is restrictive

F.U.D.

Page 9: Inclusion And Empowerment

[ change ]

Create a shared Governance Function

SecuritySteering

CommitteeIT

Finance

HR

Sales

Legal

Page 10: Inclusion And Empowerment

[ change ]

• Security is a process inside The Company

• People, Processes, Information

• Participate in the Business

Security as “Business Risk Management”

Chief Risk Officer

Physical Security Legal Information

& IT Security

Page 11: Inclusion And Empowerment

[ change ]

Use security to enhance business

Give back to the business

Focus on:

• Efficiency & Effectiveness

• Availability

ITIL: Process Improvement, Predictability

Page 12: Inclusion And Empowerment

[ change ]

Promote a security as a cultural and behavioral change.

Focus on changing long term patterns and attitudes about security.

Focus on security enabling people, not as restricting rules.

Make security something everyone can understand and act on.

Show how security applies to all parts of life- at work and home.

Page 13: Inclusion And Empowerment

[ change ]

How do you lead to achieve this?

• Have a New Attitude

• NO FUD

• Put your business hat on!

• Think of good business practices that reflect security

• Think of business opportunities

• Be a Team Player - Include everyone on the team

Page 14: Inclusion And Empowerment

[ change: sources ]