Title: Security and your Staff
1Security and your Staff Implementing Effective
Employee Education and Awareness Programs.
Pamela Halpern Easy i, Inc
2Dont bury your head in the sand!
- The best security awareness will provide the
right messages to the right people at the right
time, provide the tools to all to practice what
has been learned and provide a mechanism to
measure progress. -
- -- Gary Sheehan
3This Session
- The Key Challenges
- Using Media Effectively
- Feedback and Measurement
4The Key Challenges
- Systems alone are not enough
- Overcoming complacency
- Different target audiences
- Delivering the program
- Ongoing program
- Cost-effective
- Measuring the results
- Demonstrating compliance
5Developing training solutions - A double challenge
- Meeting the needs of
- The Audience
- Management
6For the Audience
Learning that is
- Stimulating
- Relevant
- Accessible
- Challenging (and enjoyable?)
By creating and maintaining interest and the
motivation to learn
7For Management
Learning that is
- Efficient
- Successful
- Good value for money
- Flexible
By creating programs that are easy to implement,
manage, update and audit
8What is best?
Posters Screensavers Tests Awards Games Themes
Mascots Briefings Policy sign-off Newsletters I
ntranet Video Exec. Briefings Classroom CBT Ass
essments Brochures TBT
9What is best?
10What is best?
This depends on you!
What objectives have you set? What is the size of
your organization? What resources do you
have? What budget do you have? Can you get
management buy-in? a marketing campaign
11Technology-Based Training
- Reduced delivery costs
- Reduced training time
- Flexibility and convenience
- Self-paced and non-threatening
- Consistent content and delivery
- Accurate measurement control
- Tailored content
12An Awareness Campaign
- Core training
- Refresher training
- Ongoing awareness
13Core Training
Computer/Web-based
14Refresher Training
Reinforce Key Issues
15Ongoing Awareness
Intranet Knowledge Zones What should this mean
in practice?
A system for gathering, organizing and
communicating information and knowledge that is
- User-friendly
- Intuitive
- Flexible
16Ongoing Awareness
Information Assurance Intranet Site
17GE Capital
18Ongoing Awareness
Commitment from your users
19Ongoing Awareness
Electronic posters policy sign-off
20Ongoing Awareness
Internal Marketing - Helps to reinforce the key
messages - Can have fast and effective
results A wide range of resources can be used
21Ongoing Awareness
Internal Marketing Pens, key-rings, coasters,
awards, mouse-mats
22Ongoing Awareness
Internal Marketing Put it all together for a full
campaign...
23Feedback and Measurement
Feedback and measurement is ESSENTIAL!
Delivering awareness solutions via intranet/web
presents many options. These generally fit into
two key categories 1. Audit/tracking
system 2. Learning Management System
24Feedback and Measurement
- 1. Audit/tracking system
- built into the main training program
- provides information on the progress and
performance of each user - may allow you to export information into other
applications - generally provided free with the program
purchased -
25Feedback and Measurement
- 2. Learning Management System
- provides the infrastructure needed to track,
record, schedule and deliver corporate wide
learning - many different kinds of LMS offering different
types of functionality - allows you to manage the variety of training
programs/resources available from one central
point including, online learning, classroom
training, registration, instructor availability
etc - can be very expensive!
26Audit/Tracking System
27Feedback and Measurement
- How do you choose the right solution?
- Assess how feedback and measurement is currently
undertaken for training in other business units
perhaps a LMS is already in place? - What requirements do you and your organization
have now and in the future? - Size of organization
- Budget
- AICC/SCORM Compliant
28Learning Management System
29Learning Management System
The medieval rule of parsimony, or principle of
economy, frequently used by Occam came to be
known as Occam's Razor. The rule states that
plurality should not be assumed without necessity
or, in modern English, keep it simple, stupid.
30Why some fail?
- Lack of awareness understanding
- Lack of support
- Weak campaign not current issues
- Company culture
- Lack of effort in initial launch
- No effort to maintain a long term program
31Factors to consider for your Awareness Program
- Training needs
- Management commitment
- Platform
- Reporting requirements
- Data management and integration
- Internal marketing
- Reviews and updating
32Dont bury your head in the sand!
33Information Security Awareness
- Getting the message through
34Questions?
Pamela Halpern Easy i pamela.halpern_at_easyi.com
310 414-0731 www.easyi.com
35