• No results found

The importance of Information Security Awareness and its interdisciplinary nature its interdisciplinary nature

Chapter III – The Importance of Information Security Awareness Security Awareness

3.2 The importance of Information Security Awareness and its interdisciplinary nature its interdisciplinary nature

Given the rising level of breaches, it is more critical than ever for organizations to raise the level of security awareness by turning their users into the first line of defense.

The National Institute of Standards and Technology (National Institute of Standards and Technology (NIST), 1998)in their article “Information Technology Security Training Requirements: A Role- and Performance-Based Model, Special Publication 800-16” use the following definition for security awareness:

“Awareness is not training. The purpose of awareness presentations is simply to focus attention on security. Awareness presentations are intended to allow individuals to recognize IT security concerns and respond accordingly. In awareness activities the learner is a recipient of information, whereas the learner in a training environment has a more active role.

Awareness relies on reaching broad audiences with attractive packaging techniques. Training is more formal, having a goal of building knowledge and skills to facilitate job performance.”

Rebecca Herold (2005) at her book “Managing and Information Security and Privacy Awareness and Training Program”, defines awareness as”

“a learning process that sets the stage for training by changing individual and organizational attitudes to realize the importance of security and the adverse consequences of its failure.”

According to Information Security Forum (ISF), security awareness is:

“the degree or extend to which every member of staff understands:

 the importance of information security

 the levels of information security appropriate to the organization

 their individual security responsibilities

and acts accordingly.” (Information Security Forum, 2002)

All of the above widely accepted definitions have a lot of similarities.

Awareness has to do with realization of information security threats so people are aware of what may happen as a result of poor information security. It also has to do with willingness to accept appropriate behavior to counter take the various threats and attacks. So awareness by itself has no value unless a desired change in security behavior is achieved.

In summarizing the above definitions, security awareness is a proactive measure and has to do with making end users and employees aware of how to protect personal and organizational information by applying information security practices. According to NIST, information security in terms of learning is a continuum which starts with awareness, build into training and finally evolves into education (National Institute of Standards and Technology (NIST),

1998). Awareness being at the bottom of the continuum is required by all employees. Training is required by those individuals with specific roles in the organization that require special knowledge of security threats and vulnerabilities. Finally, education applies to those individuals who have IT security as their profession. NIST clearly separates awareness from training by defining the purpose of awareness presentations as “simply to focus on security” with an objective to allow individuals recognize IT security concerns and behave accordingly.

Information security has to be managed effectively and such process requires a combination of technical as well as procedural controls in order to protect information assets. However these controls can be bypassed or abused by employees who have appropriate elevated access to information systems and who will neglect to comply with the organization’s security policy. Such behavior may also be observed on home users of information systems and is usually the result of the lack of awareness in regard to information security threats. Such incidents caused by employee mistakes result in far more damage to businesses every year than external attacks.

In order to safeguard a company against all IT threats requires adequate attention to many aspects of security Among others it is important to maintain a high level of employee awareness among all levels and not just among staff whose work is IT related (Kaspersky Lab, 2013). Ernst & Young’s Global Information Security Survey 2013 recognizes that organizations are moving towards the right direction concerning information security but “more still needs to be done – urgently” (Ernst & Young, 2013). Awareness of security threats and risks is a crucial step since it is recognized as a method that drives

improvement. Taking into consideration that companies do not have the skilled resources to support their needs (only a 30% of the companies according to the report are considered mature or very mature in terms of security awareness, training and communication), the establishment of an information security awareness program that will foster the appropriate security culture throughout all levels of the organization is one of the leading practices that will enable InfoSec improvement (Ernst & Young, 2013).

Finally, information security awareness as a preventive measure is considered as an important prerequisite by several international standards. BSI‘s self-assessment questionnaire concerning ISO/IEC 27001:2013, recognizes that everyone within the organization must be aware of the importance of information security policy and adhere to it through proper awareness, education and training (BSI, 2013). Also COBIT 5 realizes the importance of a knowledge-sharing culture through an information training and awareness program as a prevention measure for data loss (ISACA, 2012; ISACA, 2013).

It is evident that the protection of confidential information from unauthorized access along with secure online behavior, is very important for every organization and individual. As it is important to invest in technology to protect your assets, it is also equally important to invest in the education of employees.

Since the company’s information security team cannot provide all the necessary security measures for all kinds of threats, an overall enterprise awareness plan is required in order to cope with the wide variety of incidents an organization might face and such plan requires the active participation of every employee (Olzak, 2006).

Herold (2005) also realizes that an information security awareness program not only adds an extra level of strength in coping with today’s threats and attacks but can also be an important component of an organization’s business success. More specifically, corporate reputation can be severely damaged because of the lack of a security awareness program due to the following reasons:

 Regulatory requirements compliance: There is an increasing number of laws and regulations that require some form of training and awareness activities to occur within the organization. Examples of these training activities include frequency of organizational communication concerning personnel policies and procedures, ongoing and constantly updated awareness initiatives with appropriate measurement of desired results, training on ethical work practices, etc.

 Customer trust satisfaction and corporate reputation: Customers and organizational partners are bombarded everyday with privacy breaches from the media. Protection of customer privacy is one of the most important issues companies are facing today. Providing a personnel awareness program on how to deal and safeguard personal identifiable information will establish customer trust for existing customers and attract new ones. Also it will ensure the successful building of a good corporate reputation since personnel and business partners follow the right security precautions to reduce the risk of compromising personal information.

 Due diligence: Due diligence has to do with the assurance that management adequately protects corporate assets such as

organizations to have established internal controls that support the privacy and security of sensitive information. Such laws and regulations can be a powerful motivator for the implementation of an employee awareness program.

 Accountability: Employee accountability is a crucial component for the success of an information security program. It is generally the norm that personnel performance is measured by certain activities which eventually impact career advancement. If information security and privacy is connected with personnel performance, then personnel accountability is more clearly understood and are more likely to comply.

Such accountability can be achieved through well-organized security awareness programs.

From the above it is evident that the purpose of information security is to protect organizational assets that are critical for its success and business continuity and at the same time reduce business damage by preventing and minimizing the impact of security incidents. Information security can be achieved by both technical and non-technical aspects. As part of the non-technical aspects, the human component has been recognized to have an important role in information security since the only way to reduce security risks is through making employees more information security aware.

3.3 Assessing the state of the art in building security