<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Training users? Do they still do what you tell them NOT to do?</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-trenches/training-users-do-they-still-do-what-you-tell-them-not-to-do/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-trenches/training-users-do-they-still-do-what-you-tell-them-not-to-do/</link>
	<description></description>
	<pubDate>Sat, 28 Nov 2009 13:00:05 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Stiltner</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/training-users-do-they-still-do-what-you-tell-them-not-to-do/#comment-30</link>
		<dc:creator>Stiltner</dc:creator>
		<pubDate>Thu, 28 May 2009 19:10:29 +0000</pubDate>
		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/training-users-do-they-still-do-what-you-tell-them-not-to-do/#comment-30</guid>
		<description>Hah, now thats a good story.  That one I can truly appreciate.
I will parrot the sentiment that far too many people are either A) Uneducated or B) Unaware of how important security is in an end user scenario.

Administrators can do so much, but social engineering has to take the rest of the slack up and help those people learn these things, and not just to sign a piece of paper to CYA, that to me is more dangerous than leaving them ignorant to the importance.

I've been through corporate security training, it was all of 10, maybe 15 minutes, sign the paper and go on with life.  That kind of policy is to me weak, and only meant to appease attorneys.  I realize there's costs associated with training, but how do those compare to the costs associated with a breach related to uneducated personnel.</description>
		<content:encoded><![CDATA[<p>Hah, now thats a good story.  That one I can truly appreciate.<br />
I will parrot the sentiment that far too many people are either A) Uneducated or B) Unaware of how important security is in an end user scenario.</p>
<p>Administrators can do so much, but social engineering has to take the rest of the slack up and help those people learn these things, and not just to sign a piece of paper to CYA, that to me is more dangerous than leaving them ignorant to the importance.</p>
<p>I&#8217;ve been through corporate security training, it was all of 10, maybe 15 minutes, sign the paper and go on with life.  That kind of policy is to me weak, and only meant to appease attorneys.  I realize there&#8217;s costs associated with training, but how do those compare to the costs associated with a breach related to uneducated personnel.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- dynamic -->