🛠️ This is a sandbox environment
Published November 14, 2011 | Version v1

Embedding security messages in existing processes: a pragmatic and effective approach to information security culture change

Authors/Creators

  • 1. ROR icon European Organization for Nuclear Research

Description

Companies and organizations world-wide depend more and more on IT infrastructure and operations. Computer systems store vital information and sensitive data; computing services are essential for main business processes. This high dependency comes with a number of security risks, which have to be managed correctly on technological, organizational and human levels. Addressing the human aspects of information security often boils down just to procedures, training and awareness raising. On the other hand, employees and collaborators do not adopt security attitude and habits simply when told to do so – a real change in behaviour requires an established security culture. But how to introduce a security culture? This thesis outlines the need of developing or improving security culture, and discusses how this can be done. The proposed approach is to gradually build security knowledge and awareness, and influence behaviours. The way to achieve this is to make security communication pervasive by embedding security messages, warnings and advice in human and technological processes, and situations that already exist within an organization.

Files

CERN-THESIS-2010-250.pdf

Files (5.2 MB)

Name Size Download all
md5:1fc10ac5658b2a592a249767d7eaf97f
2.3 MB Preview Download
md5:27bf747f4cc9e2cc6717e10f069632be
2.9 MB Download

Additional details

Additional titles

Translated title
Security culture change

Identifiers

CDS
1399469
CDS Report Number
CERN-THESIS-2010-250
Aleph number
000719224CER

Linked records