6,315 pts.
 Open IT Forum: How do you raise awareness for security compliance in the enterprise?
We've gotten your opinions on network security from the hardware and software side, but now we want to know what you're doing for compliance. From what your compliance policies are to the creative ways you raise awareness about those policies, share your stories and you might get 100 knowledge points in time for the final day of our Xbox 360 contest (tomorrow!). Do you make posters? Have security drills? Seminars? Do you send your employees to cyber security university? Let us know in the discussion area or send me an email at Melanie@ITKnowledgeExchange.com.

Software/Hardware used:
ASKED: December 14, 2010  5:48 PM
UPDATED: December 17, 2010  6:47 PM

Answer Wiki:
Last Wiki Answer Submitted:  Be the first to answer this question.
All Answer Wiki Contributors:  Be the first to answer this question.
To see all answers submitted to the Answer Wiki: View Answer History.


Discuss This Question:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _


 

We have posted multiple articles in our Department and Corporate newsletters. We give reminders and suggestions of how to protect sensitive information and what is and is not allowed concerning internet and email use. We have a corporate email encryption product in place and people were notifed by email and newsletter articles about how that works and how to use it. It is also included in our yearly compliance test we all have to take.

 56,975 pts.

 

Do you send your employees to cyber security university?

No, but we have had someone studying for CISSP certification at all times in recent years.

Because automating network security, system auditing and compliance is our business, we maintain regular attendance at a couple auditor conventions and host training for them. The interactions with auditors lets us learn from them while simultaneously keeping some of them up on what they should be looking at. Learning directly from them adds dimensions that aren’t obvious from reading books, articles and web presentations or from studying regulations (all of which are also done).

Tom

 107,995 pts.

 

I just held an end-of-year pop quiz for my users in an HR meeting. They were excited and gave great answers! They do want to learn if you give them something that applies to them outside of work! Social engineering & phishing awareness are good topics.

 32,645 pts.