pinar akkaya - the human dimension

37
> The Human dimension human aspect of information security

Upload: pinar-akkaya

Post on 01-Nov-2014

812 views

Category:

Technology


4 download

DESCRIPTION

Human Aspect of Information Security > Presentation done on 12 October, 2011 E-Crime Event, Istanbul

TRANSCRIPT

Page 1: PINAR AKKAYA - The Human Dimension

> The Human

dimension

human aspect of information security

Page 2: PINAR AKKAYA - The Human Dimension

Guess You’ll all agree Guess You’ll all agree with me that….

Page 3: PINAR AKKAYA - The Human Dimension

bad information security

means

bad company securitybad company security

lost credibility

Page 4: PINAR AKKAYA - The Human Dimension

we must be sure that

we protect our data, our we protect our data, our

commercial secrets, our assets

and our business transactions

Page 5: PINAR AKKAYA - The Human Dimension

YOU DO EVERYTHING TO YOU DO EVERYTHING TO YOU DO EVERYTHING TO YOU DO EVERYTHING TO MAKE THIS HAPPEN MAKE THIS HAPPEN MAKE THIS HAPPEN MAKE THIS HAPPEN MAKE THIS HAPPEN MAKE THIS HAPPEN MAKE THIS HAPPEN MAKE THIS HAPPEN

FOR SUREFOR SUREFOR SUREFOR SURE

Page 6: PINAR AKKAYA - The Human Dimension

but…

EMPLOYEES WORK WITH COMPANY DATA,

COMPANY SYSTEMS, THEY ARE IN TOUCH WITH

CLIENTS, SERVICES AND PRODUCTS.

THEY NEED TO UNDERSTAND THE BASIC

PRINCIPLES OF INFORMATION SECURITY.

Page 7: PINAR AKKAYA - The Human Dimension

HUMAN ERROR IS THE

42%

Fact:

CAUSE OF 42% OF ALL

SECURITY BREACHES

ISC2 White Paper : Securing the Organizations: Creating A

Partnership Between HR and Information Security

Page 8: PINAR AKKAYA - The Human Dimension

50% of

respondents think that

their employees had

Information security is one of

the biggest challenges a business faces today.

55% of

companies used

Ref: Checkpoint Technologies&The Ponemon Institute Survey 2011 >>

2,400 IT security staff across the world

their employees had

little or even no

awareness of data

protection issues or

corporate security policy.

companies used

over 7 different

vendors to keep

their network

secure.

Page 9: PINAR AKKAYA - The Human Dimension
Page 10: PINAR AKKAYA - The Human Dimension

When does “an employee”When does “an employee”?becomes a RISK

Page 11: PINAR AKKAYA - The Human Dimension

123456

Password

?Do you know what these are

Password

iloveu

Page 12: PINAR AKKAYA - The Human Dimension

I mean…

The gap between you guys

And your average And your average employee

is

HUGE

Page 13: PINAR AKKAYA - The Human Dimension

We don’t know

Fact:

We don’t know As much as you do

Page 14: PINAR AKKAYA - The Human Dimension

, ,Paper pen letter

typewriter

computer

,internet e-mail

2.0,Web social media

Virtual communities

Page 15: PINAR AKKAYA - The Human Dimension

People move…

Both in real and virtual world…

!And they create risk

With or without knowing it

Page 16: PINAR AKKAYA - The Human Dimension

87,5% of large businesses have a security policy in place.

67% of the companies that give a high priority to security also had a security policy.

A big majority of companies take steps to raise awareness among employees.

More than 50% allow staff to access their systems remotely.

The proportion of businesses restricting internet access dropped by 50%.

A picture…

The proportion of businesses restricting internet access dropped by 50%.

Now only fewer than 10% gave no access to the internet.

Employees are increasingly being targeted by "social engineering" attacks.

Businesses are becoming more concerned about what was being said about them on

social networking sites.

More than 80% of large companies blocked access to inappropriate websites.

86% logged and monitored staff access to the internet.

Research by PWC UK , 2010

Page 17: PINAR AKKAYA - The Human Dimension

more exposure,

more action,

more knowhow sharing,

more interactionmore interaction

The Return is big but The Return is big but The Return is big but The Return is big but the Risk is big toothe Risk is big toothe Risk is big toothe Risk is big too

Page 18: PINAR AKKAYA - The Human Dimension

your employees

can fast become

weakestthe weakest link in your information

security

Page 19: PINAR AKKAYA - The Human Dimension

changing employee behaviour

is the key

to improving information security.

Page 20: PINAR AKKAYA - The Human Dimension

The big howThe big how

Page 21: PINAR AKKAYA - The Human Dimension

EMAIL SECURITY

INTERNET SECURITY

Offer them a clear framework

INTERNET SECURITY

DATA SECURITY

ASSETS SECURITY

Page 22: PINAR AKKAYA - The Human Dimension

?Do you have policies

?Why

Page 23: PINAR AKKAYA - The Human Dimension

Customize the access according to the skills and needs of the employees

customize the risk

But standardize your policies

Page 24: PINAR AKKAYA - The Human Dimension

The worst way to communicate a policy iscommunicate a policy isPublishing it

Page 25: PINAR AKKAYA - The Human Dimension

, , :Educate educate educate

have your employees build have your employees build the “awareness” muscle

Give people good habits

Page 26: PINAR AKKAYA - The Human Dimension

Communicate your best practices

Page 27: PINAR AKKAYA - The Human Dimension

Create an awareness :culture :culture

let it be a dialogue

Page 28: PINAR AKKAYA - The Human Dimension

Make it formal: Make it formal:

it is serious

Page 29: PINAR AKKAYA - The Human Dimension

,Make it simple

,make it fun ,make it fun

make it participative

Page 30: PINAR AKKAYA - The Human Dimension

Make it a management issuemanagement issue

Page 31: PINAR AKKAYA - The Human Dimension

Be fully fully fully fully proactiveBe fully fully fully fully proactive

Page 32: PINAR AKKAYA - The Human Dimension

Tell them

=Personal = professional

Page 33: PINAR AKKAYA - The Human Dimension

Prohibiting LimitingBanningis not your key to successis not your key to success

trust

Page 34: PINAR AKKAYA - The Human Dimension

WIIFM?

answer

WIIFM?

Page 35: PINAR AKKAYA - The Human Dimension

?Does hr talk about these

I am afraid not…

& *Hr it partnership

I am afraid not…

Legal base remains unclear too…

Page 36: PINAR AKKAYA - The Human Dimension

You have to be security and policy mentor

Your employees have to be security and policy literatesecurity and policy literate

Your company has to be security and policy fluent

Page 37: PINAR AKKAYA - The Human Dimension

E-mail:

[email protected]

LinkedIn:

http://tr.linkedin.com/in/pinarakkaya

get connected

http://tr.linkedin.com/in/pinarakkaya

Twitter: http://twitter.com/PINARAKKAYA

http://twitter.com/lifesocialmedia

http://tr.linkedin.com/groups/hrleadersturkey