by Kristy Westphal

Managers: Get on the security bandwagon

News
Apr 23, 20104 mins

Dear Managers: Help Wanted!

No, this isn’t a job posting. More of a plea for participation. The Information Security staff is working ever so hard to make sure your organization’s data is safe, but they can’t do it alone! They need support from every level of the organization … and a lot of this support depends on the immediate participation of you managers. Your employees won’t want to follow the rules if you aren’t up to speed on them and you don’t live them yourself.

Is network security a dead career?

In other words, managers, we need to walk the talk.

We are all overly busy, so what’s the most efficient way to get started? Begin by asking for and reading our information security policies. If you have any questions whatsoever or need any translation, reach out to us. We live and breathe these policies and can quickly clarify any questions that you have (and will be tickled to do so!).

What’s next? You have some method of communicating to your staff on a weekly, bi-weekly or monthly basis, right? So spend 10 minutes at the next meeting reviewing the policies. Let them know how important they are. Be honest with them: some of the policies are a pain in the neck, but explain why they are in place. For example, let’s take a look at the password policy.

Strong passwords frustrate everyone. Yes, even information security people get frustrated by them! However, passwords need to be complex and need to be changed frequently and need to vary from system to system because they are oftentimes our only defense against unauthorized access.

Sharing them with others or letting someone else use your login session while you aren’t watching can not only hurt you by making it look like you did something you didn’t, but could potentially hurt the entire organization if someone causes fraudulent transactions and harms the organization’s reputation. Then everyone is out of a job.

All those policies are truly written for a reason, and it helps all of us if we take the time to understand them and be able to properly abide by them.

Once the initial review is over, you can organize future meetings around additional reminders. We may require annual security refresher training, and if the big shots determine that is a must, then managers, be the first to have it done. Make sure all your staff gets on board as soon as possible. Emphasize its importance and answer or find answers to any questions that come from the training.

Lastly, and possibly most importantly, find one security policy that you can work into a new habit at least once a month. Whether it’s training yourself to lock that workstation screen before you walk away, or rebooting to install patches or volunteering to be a data owner for a new application to ensure proper authorization of users … find a way. If your staff sees you doing this, they will feel more comfortable mirroring similar behavior, which will make the organization more secure.

Improving security is more about people than technology. Leaders of people in organizations large and small can help to instill good security habits and reduce risk. But the leaders have to believe. You have to want that job before you can help others want it too.

Westphal, a 17 year IT professional, is an information security consultant with a large payment processing company. Skilled in troubleshooting and process analysis, specific expertise in security areas includes forensics, operating system and network security, intrusion detection, incident handling, vulnerability analysis and policy development. Westphal has been a CISSP since 2001 and a CISA since 2008. You can reach her at kmwestphal@cox.net.