17
Security Awareness Chris Merkel Director, IS Security Brunswick Corporation

Security Awareness - Defined, Managed and Measured

Embed Size (px)

DESCRIPTION

We need to have an understanding of what actually constitutes "awareness". In addition, we also need to be able to measure people's awareness, which isn't always easy.

Citation preview

Page 1: Security Awareness - Defined, Managed and Measured

Security AwarenessChris MerkelDirector, IS SecurityBrunswick Corporation

Page 2: Security Awareness - Defined, Managed and Measured

Why “Awareness”?

…when I have an IDS/IPS, UTM Gateway, Encryption, DLP, Vuln Scanning, Patch Management, AV, HIDS, WAF, SEIM, Secure Code Review, Whitelisting, MDM, cable locks, lo-jack and epoxy in all of my USB ports!!!!

Page 3: Security Awareness - Defined, Managed and Measured

Hint: You don’t have a technology problem.

“A computer lets you make more mistakes

faster than any invention in human history – with the

possible exception of handguns and tequila.”

- Mitch Ratliff

Page 4: Security Awareness - Defined, Managed and Measured

What is awareness?

Page 5: Security Awareness - Defined, Managed and Measured

This is not awareness:

Page 6: Security Awareness - Defined, Managed and Measured

Neither is this:

92%

3% 5%

Percentage of US Employees Completing Security Awareness Module in the Past

12mo.

Complete

Incomplete

COMPLIANT

Page 7: Security Awareness - Defined, Managed and Measured

…or this:

Page 8: Security Awareness - Defined, Managed and Measured

Awareness is knowledge:

•That *you* are being targeted as part of a larger campaign to steal something.

•Within your specific business risk context.•Which will require you to be able to

identify suspicious “things”.•To understand and avoid a negative

outcome.•By taking appropriate action.•Or immediate corrective actions, if a

thoughtless or incorrect choice is made.

Page 9: Security Awareness - Defined, Managed and Measured

Excellent Awareness

Poster

What’s the problem?

How does it affect me?

What should I do?

Page 10: Security Awareness - Defined, Managed and Measured

Does Awareness “Work”?

Common criticisms:•One click, by one user, and you’re

compromised, so why bother?•We told them not to do that, and they still

did it.•They didn’t remember our advice.

Page 11: Security Awareness - Defined, Managed and Measured

Our Goal:Harm Reduction,Not Elimination

Page 12: Security Awareness - Defined, Managed and Measured

Awareness Ideas

•Publish informational content in your IT knowledgebase / wiki.

•Periodic informational emails.•“Point of failure” education on your

internet gateways.•“Coaching” people when they visit sites

common to scams.•Internal phishing campaigns.•Scam bounty programs.•Annual, self-paced, awareness training.

Page 13: Security Awareness - Defined, Managed and Measured

Measuring Efficacy – A Must

The best possible outcome is that *nothing* happens. Measure that.

Next best option – reduction in bad things:- Web content filter hits.- Phishing assessments.- Anti-virus hits / infections.

Page 14: Security Awareness - Defined, Managed and Measured

But….

Correlation ≠ Causation

Be rigorous with your data.

Page 15: Security Awareness - Defined, Managed and Measured

Educational Resources:• SANS Securing the human blog / newsletter• US-CERT National Cyber Awareness System• Krebs on Security• Office of the National Counterintelligence

Executive• NIST Computer Security Resource Center• Infragard Center for Information Security

Awareness• FTC – Onguard Online• StaySafeOnline.org - National Cyber Security

Alliance

Page 16: Security Awareness - Defined, Managed and Measured

Phishing Resources

•Free: SPT•Commercial:

▫Phish5▫Phishline▫Phishme

Page 17: Security Awareness - Defined, Managed and Measured

Thank You!Q&A