how to build and maintain security culture in any organization

28
SECURITY CULTURE by Kai Roer ISACA Nordic Conference, Oslo, 2014

Upload: kai-roer

Post on 23-Aug-2014

2.390 views

Category:

Leadership & Management


0 download

DESCRIPTION

This is the slides from a presentation I gave at the ISACA Nordic Conference in Oslo 2014, where I discuss what culture is, why it is important, and propose one way to build and maintain security culture by using the Security Culture Framework. You can read the transcript at my blog: http://roer.com/2014/04/08/build-maintain-security-culture/ which will help you make more sense of the slides!

TRANSCRIPT

Page 1: How to build and maintain security culture in any organization

SECURITY CULTUREby Kai Roer

ISACA Nordic Conference, Oslo, 2014

Page 2: How to build and maintain security culture in any organization
Page 3: How to build and maintain security culture in any organization

SECURITY CULTURESay what…?

Page 4: How to build and maintain security culture in any organization

WHAT IS CULTURE?

the ideas, customs, and social behavior of a particular people

or society

Ref: Oxford Dictionary

Page 5: How to build and maintain security culture in any organization
Page 6: How to build and maintain security culture in any organization
Page 7: How to build and maintain security culture in any organization
Page 8: How to build and maintain security culture in any organization
Page 9: How to build and maintain security culture in any organization
Page 10: How to build and maintain security culture in any organization
Page 11: How to build and maintain security culture in any organization

WHAT IS SECURITY?

• the state of being free from danger or threat

• the state of feeling safe, stable, and free from fear or anxiety

Ref: Oxford Dictionary

Page 12: How to build and maintain security culture in any organization
Page 13: How to build and maintain security culture in any organization
Page 14: How to build and maintain security culture in any organization
Page 15: How to build and maintain security culture in any organization
Page 16: How to build and maintain security culture in any organization
Page 17: How to build and maintain security culture in any organization
Page 18: How to build and maintain security culture in any organization

SECURITY CULTURE

the ideas, customs, and social behavior of a particular people or society, that helps them

being free from danger or threat

Ref: K. Roer

Page 19: How to build and maintain security culture in any organization
Page 20: How to build and maintain security culture in any organization
Page 21: How to build and maintain security culture in any organization

CREATINGa Security Culture Program

Page 22: How to build and maintain security culture in any organization

INTRODUCING: THE SECURITY CULTURE FRAMEWORK

Page 23: How to build and maintain security culture in any organization

WHERE TO START

1. Set up your team

2. Define your goals, and how to know you reach them (To-Be)

3. Measure your current status (As-Is)

4. Define target audience(s)

5. Choose relevant topic(s) and activities

6. Plan and execute

7. Measure and Revise

8. Restart

Page 24: How to build and maintain security culture in any organization

WHY A PROGRAM

• Culture is constantly evolving

• Organizations change

• People change

• Not one training to save them all!

Page 25: How to build and maintain security culture in any organization

MORE THAN TRAINING

• Security Culture must be nurtured

• Support business

• Create understanding && Awareness

• On-going

• One step at the time

Page 26: How to build and maintain security culture in any organization
Page 27: How to build and maintain security culture in any organization

THANKS, ISACA 2014!• http://theroergroup.com

• http://roer.com

• https://scf.roer.com

• @kairoer

Page 28: How to build and maintain security culture in any organization

SOURCES OF INFORMATION

• The Security Culture Framework project

• Research

• SANS

• The Analogies Project

• The Security Awareness Framework project