4,265 pts.
 Educating your users on security policies
Open IT ForumWhat measures do you/your organization take to educate employees on network security policies? Do you include this information in new hire training? Do you hold special training? Does your include any unique or particular provisions?

Software/Hardware used:
ASKED: November 10, 2009  7:37 PM
UPDATED: November 25, 2009  5:06 AM

Answer Wiki:
This has come up recently where I work. There has been little guidance on computer/communications security. New hires will be made aware of policy and we are set to train the current employees within the next month. I think the biggest aspects of security is making sure that personnel understand why certain protocols are being put into place and enforced. It is easier for people to comply with rules that they have an understanding on. There are no truly unique or particular provisions in what we are trying to accomplish. We are, however, trying to combine these efforts with proper business practices and IT usage. Examples being, do not save movies on your company laptop, do not download pirated music, etc. Many of these things should go without saying, but if you can show a correlation between streaming video and a slow internet connect for the neighbor, people seem to listen a little better. The biggest step in finalizing full implementation of policy is enforcement. One can write beautifully articulated rules that hit at finite points or give a step by step remedial action plan, but unless management is going to take the corrective action needed to fix discrepancies, all of these actions serve only a litigious purpose. Sorry to drone on. +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ New employees receive a Computer User Policy which has a security section. This must be read and signed. Any questions regarding the policy are discussed with an I.T. staffer. We also have "university days" which is a company wide education session, IT and security is covered in length. These days are mandatory attendance days; those with valid excuse receive private instruction. We have several "automated" security features/protocols that essentially take care of everything else. All remove-able storage for example is blocked, web-filtering is active, e-mail security is strict. Although some may view our policies as lenient, they cover the bases thoroughly and we've not had a problem yet. Hope this helps! -Schmidtw
Last Wiki Answer Submitted:  November 10, 2009  9:43 pm  by  XENOPHON22   2,325 pts.
All Answer Wiki Contributors:  XENOPHON22   2,325 pts.
To see all answers submitted to the Answer Wiki: View Answer History.


Discuss This Question:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _


 

Anyone who doesn’t comply is confronted nearly immediately. If i’m feeling so devious, I’ll trace the MAC address of the abuser and shut off the port. :D

-Schmidtw

 11,205 pts.

 

The policy is sent through mail to all as and when updated. it is also published on company intranet.

 8,200 pts.