As we all know by now, the human factor is crucial to enterprise security. Cyber attacks routinely exploit vulnerable human behaviors to gain entry, since organizations must trust their own people—or at least some of them—with access to critical systems.
Humans make decisions on risk tradeoffs, funding for security programs, adherence to policies, and hiring, factors which impact the organization’s security posture in many ways. From the newest intern to the chief executive, all members hold the power to harm, or to help, the security of sensitive data and essential systems.
Acknowledging this is a necessary but insufficient step. The humans we rely on must know what to do about all of this. Given that cybersecurity is neither the expertise nor passion of most people, there must be an easy-to-understand and easy-to-do set of actions that everyone can perform to do their part.
It turns out that for all of the resources available on security awareness and training, there is precious little available on security guidance for employees based on their business functions. That is, guidelines for people based on their job role: security guidelines for Finance and Administration professionals or security guidelines for Legal & Compliance workers.
It was to address this need that the Workforce Management subgroup of the National Initiative for Cybersecurity Education (NICE) launched a project to draft guidelines for all members of an organization based on business function.
NICE is a program of the National Institute of Standards and Technology (NIST), the lead federal agency for maintaining the Framework for Improving Critical Infrastructure Cybersecurity (commonly known as the Cybersecurity Framework, or CSF), among other standards. (Many readers may also be familiar with NIST for the Special Publication 800 series, which provides detailed technical standards for security.)
The Workforce Management subgroup, part of the (Read more...)
*** This is a Security Bloggers Network syndicated blog from The State of Security authored by Maurice Uenuma. Read the original post at: https://www.tripwire.com/state-of-security/security-data-protection/cyber-security/cybersecurity-is-everyones-job/