True Security Requires Extensive End-User Training

Opinion
Dec 7, 20094 mins

Do you know your company's security policy?

I am writing this column on my company-owned laptop while sitting on (mighty uncomfortable) bleachers in a middle-school gym waiting for my daughter’s basketball game to start. This is nothing unusual in this era of the virtual workplace.

But it got me thinking about something extremely important: To what extent do I know all of our security policies governing my use of this laptop while working away from the comfortable confines of my office? Or, even in the office—what applications can I install and use, and what Web sites are acceptable? And, what kind of information can I safely share with my colleagues over collaborative applications, such as instant messaging or Web conferencing?

Fortunately, I know most of the answers to the above questions because security is so vital to our CIO. He trains us on what we can and cannot do, and he has a detailed, written security policy that is easily accessible. When we falter, he reminds us which chapter and verse of his security policy we have or are about to violate. (One fond memory was the one time I told him to hang on during an IM chat so I could send him a password. My phone rang almost instantly, along with a “NO!!!!” response over IM, and I received an appropriately stern lecture.)

So why do I know only most of those answers? Human nature. We only retain so much information, and we forget some important rules that could compromise corporate data and applications.

When all employees work in an office, it’s easier for the IT staff to control how employees use the infrastructure. For example, policy-based controls can dictate what applications which employees can access from that location. Further, desktop virtualization helps IT staffs better control security because the apps don’t reside on the laptop itself.

But when employees are working beyond the traditional borders of a network—say in an airport or hotel room, or even from their home WLAN—control becomes more sketchy. Can your employees’ kids use their computers, and even if not, can you control whether they do? Can employees access sensitive data from a public WLAN at an airport? Should they keep a broadband access line connected to their laptop in a hotel overnight?

Security policies vary from company to company, depending on their risk tolerance, availability of security and monitoring tools, the type of company (public, private, industry, etc.), and the type of connectivity (ie., Are their direct links to business partners?). Once the company determines its risk tolerance and develops or updates its security policy, it must consider how the world of borderless networking affects that policy. Then, follow these guidelines:

-Publish the security policy in an easy-to-find location (secure wiki?), available to all employees.

-Make it easy to read and understand. Companies that write the policy in confusing legal lingo will have less success than those that write in a straight-forward, easy-to-understand manner.

-Segment the security policy by type of worker or job function to make it easier for employees to look up what’s relevant to them. Specifically, have a policy with a summary followed by details for virtual workers. What can and can’t they do from the road?

-Train, train, train. Conduct regular training sessions and refresher courses. Not only will this help employees remember the rules, but it will help you update the policy when questions arise around which there is no corporate policy.

-Update the policy with any new applications. For example, if you’re adding IM to the corporate applications, explain policies such as: you shouldn’t give passwords over IM (unless, of course, you’re using encrypted IM and that fits within the company risk tolerance).

-Make sure employees know the ramifications for not following policy, and follow through with said ramifications when someone breaks the rules. Otherwise, no one will take the policy seriously.