We've gotten
your opinions on network security from the hardware and software side, but now we want to know what you're doing for compliance.
From what your compliance policies are to the creative ways you raise awareness about those policies, share your stories and you might get 100 knowledge points in time for the final day of our Xbox 360 contest (tomorrow!).
Do you make posters? Have security drills? Seminars? Do you send your employees to
cyber security university? Let us know in the discussion area or send me an email at
Melanie@ITKnowledgeExchange.com.
Software/Hardware used:
ASKED:
December 14, 2010 5:48 PM
UPDATED:
December 17, 2010 6:47 PM
We have posted multiple articles in our Department and Corporate newsletters. We give reminders and suggestions of how to protect sensitive information and what is and is not allowed concerning internet and email use. We have a corporate email encryption product in place and people were notifed by email and newsletter articles about how that works and how to use it. It is also included in our yearly compliance test we all have to take.
Do you send your employees to cyber security university?
No, but we have had someone studying for CISSP certification at all times in recent years.
Because automating network security, system auditing and compliance is our business, we maintain regular attendance at a couple auditor conventions and host training for them. The interactions with auditors lets us learn from them while simultaneously keeping some of them up on what they should be looking at. Learning directly from them adds dimensions that aren’t obvious from reading books, articles and web presentations or from studying regulations (all of which are also done).
Tom
I just held an end-of-year pop quiz for my users in an HR meeting. They were excited and gave great answers! They do want to learn if you give them something that applies to them outside of work! Social engineering & phishing awareness are good topics.