Building a Culture of Security
Agenda ➢ What is a Culture of Security? ➢ Regulatory Requirements ➢ Cyber Hygiene ➢ How to Develop a Culture of Security
What is a Culture of Security ➢ A set of values, shared by everyone in an organization, that determine how people are expected to think about and approach security 1 ➢ Benefits ➢ Reduced cyber incidents ➢ Risk reduction ➢ Increased compliance ➢ Engaged workforce 1 Developing a Security Culture, Center for the Protection of National Infrastructure
Regulatory Requirements
Cyber Hygiene Policies Security Awareness Least Privilege Patching Authentication Endpoint Protection Encryption Network Segmentation
How to Develop a Culture of Security ➢ Acknowledge a ➢ Leadership Buy-in ➢ Training need ➢ Leaders ➢ Employees ➢ Identify a person understand risks understand the need to lead the change ➢ Communicate, ➢ Daily practices ➢ Establish a vision Communicate, consider security – for the end state Communicate second to Safety
How to Develop a Culture of Security Crawl ➢ Change doesn’t happen fast ➢ Develop a vision to race to
How to Develop a Culture of Security Walk ➢ Start at the top ➢ Build a marketing plan
How to Develop a Culture of Security Run ➢ Education ➢ Security “Just Happens”
How to Develop a Culture of Security Conclusion
Culture of Security Questions
Recommend
More recommend