• No results found

The status quo

7.4 Proposed additions to the standard

7.4.4 IS education, training and awareness

Although IS education, training and awareness are discussed in section 8.2.2 of the ISO 17799 standard, special care must be taken insofar SE issues are concerned. The reason for this is that what is described in section 8.2.2 has to do with solid facts that are well documented and is geared towards informing all parties involved on their obligations and responsibilities stemming from that factual documentation. An approach that will be effective in providing education and raising awareness on SE-related issues must be quite different.

The notion of SE can not readily be covered in full by mere reference to relevant documentation nor can it be exhausted in any document. Instead, the personnel receiving the training must be exposed to as many facets of the SE problem as possible, in order to form an esoteric understanding of the issues involved and be able to extrapolate and synthesise in situations of attack. It is this author's opinion that employees should not be given access to the organisation's information system if they have not completed a security education course in addition to the required "basic skills" course needed to operate within the bounds of the organisation's information system. Although this may sound as excessively cautious to the administration's ears given that for the sake of efficiency all new employees must become productive from their first day of employment, it is unarguably impossible for an employee to uphold the security of an information system if that employee is unfamiliar with the operation of the system and/or lacks security education. On the other

Chapter 7 180

hand it should not be considered that by exposing an employee to any single security course the problem of upholding security is resolved. Security education must be continuous and the latest updates must be methodically presented to the employees. This is the only way to achieve the raised level of awareness necessary to effectively withstand and deflect SE attacks. Applied psychology could also be used to raise awareness on SE issues along the lines described previously in this work. This can be accomplished by employing direct and indirect means to psychologically "nudge" the employees in the right direction in the fight against SE. Such an approach may include messages at workstation boot-up, circulars, notices etc.

Obviously this is one control that should involve a multi-disciplinary approach to bear fruit.

What should not be overlooked in the context of building security awareness and training for security, is the promotion of ethical standards in the workplace. This should be carried out according to the discussion presented in earlier chapters and follows from the reasoning that in a work environment where the ethical level is high, the circumstances are such that the job of the Social Engineer becomes more difficult. Again, for the promotion of ethical standards to be successful, a multi-disciplinary approach is needed.

7.5 Concluding Remarks

It should be clear by the analysis presented here that the issues pertaining to Social Engineering are not directly covered by the guidelines of the ISO/IEC 17799:2005 information security standard. Furthermore, from the study of the standard it can be deduced -in a qualitative way- that no part of it was written with Social Engineering in mind. Hence, the whole standard is not geared towards dealing with Social Engineering in particular. However, the controls and guidelines presented in the standard, deal with a large part of the types of vulnerabilities stemming from Social Engineering in an effective, albeit indirect, way. By providing subsections in the existing clauses where the SE

Chapter 7 181

aspects of individual controls or control groups are discussed along with adding new sections or clauses containing controls that are specific to the SE methods of attack, the standard will surely benefit. Apart from the introduction of new controls, new sections may even include and/or re-phrase existing controls as it is necessary to place new and existing ideas in the context of SE. If the same attention were placed on the most important issue of security training, education and awareness with respect to SE, then the effectiveness of the standard in building defenses against SE will definitely multiply in strength.

It must be noted that not all of the results of the research presented so far can be coded in the form of new or rephrased controls of the ISO/IEC 17799:2005 standard. The reason for this is that the scope of this standard can, obviously, not include the restructure of organisations or the instillation of the correct attitude towards IS. In the same sense, a policy can not suffice in inculcating the proper IS mentality in people. Hence, the enhancements to ISO 17799 that have been proposed must not be viewed as exhaustive and all-encompassing with respect to SE, although they do help towards acquiring a better level of defense against it.

Having identified the shortcomings of the ISO 17799 standard and having proposed enhancements and additions to it to better cater for risks related to SE methods, the next obvious question is how to assess the level of defenses against SE. The next chapter deals with this issue.

8.1 Introduction

In previous chapters, the principles of Social Engineering were examined, as were the social aspects of IS. This two-fold study led to the detailed examination of the IEC/ISO 17799:2005 standard from a Social Engineering point of view. One of the initial questions, however, has not yet been addressed: that of devising SE-related measurement techniques. The current chapter deals with this issue. Figure 8.1 depicts the role of this chapter within the overall structure of this dissertation.

Chapter 1: The problem of

Figure 8.1: Chapter 8 within the context of the overall dissertation structure

The need for metrics related to the Security of Information Systems in general and to the specific aspect of security against SE attacks has already been discussed in earlier chapters of this work.

Given the inherent difficulty of measuring a concept such as Information Security, it becomes much more difficult to produce quantifiable results for an even more obscure aspect of it, namely that which deals with SE.

Despite the degree of difficulty involved, the quantification of the SE aspect of Information Security is essential for the continual re-assessment of any implemented security policy and a most valuable guide in pinpointing problem issues in the defense against SE and in addressing them.

The reason this chapter deals solely with measurement techniques that are related to SE is because in all the IS literature investigated, the SE aspect of IS is inadequately dealt with and material on SE-related measurement is virtually existent, although Information Technology security metrics discussions are becoming more frequent.

Following the analysis that has been presented in the previous chapters regarding SE, this work would be incomplete if an attempt were not made to bring forward the basic principles for SE-specific metrics. This chapter is not meant to exhaustively address the issues pertaining to devising metrics for the performance of security controls against SE threats but hopefully provides a well-laid foundation to build upon in future research.