Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« It's Hard to Keep Secrets When You Entrust Them To Others | Main | Web Hackers Fined $15 Million by SEC »

If People Aren't Trained The Best Security Will Go For Naught

This week there has been much talk in the U.S. news about how Andrew Speaker, the now notorious TB patient (more specifically extensively drug-resistant tuberculosis, or XDR-TB), apparently very easily circumvented security controls to come back into the U.S. via Canada.

My heading is a paraphrase of a longer quote I really like from Charles Schumer that he made about this incident, but that also applies very nicely to all information security practices.

Reports indicate Speaker was able to cross into the U.S. through the Canadian border checkpoint because the agent there did not follow procedures.

"The Department of Homeland Security, which oversees border security, blames the agent entirely for the mistake. And it says the employee has been re-assigned to administrative duties saying, "The system worked effectively, but there was a breakdown with the employee.""

Yes, even with the best security procedures in place, if your personnel do not follow them, security breaches will occur.

I'm not sure the agent truly is "entirely" to blame; I don't know all the details involved...there is probably much more to the story than what has been reported. The agent may just be an easy scapegoat for the DHS to blame.

However, it does demonstrate that the human element truly is the weakest link in security. Not only for national security, but any place where you depend upon people to follow specific procedures in order to have security be effective and prevent incidents.

As I read about this case, and how quickly the DHS was to blame the agent "entirely," I wondered...

* How was the agent trained for these procedures?
* Did the agent just receive a memo, or did s/he receive effective, comprehensive training about how to do checks and properly respond to the warnings to the passport checks?
* Did the agent get this training only once, with no more awareness messages to follow-up, or did s/he receive ongoing awareness messages about the importance of the procedures to reinforce understanding?
* Did the agent's manager allow for procedures to not be followed without applying sanctions?
* Did other agents also routinely not follow procedures for flagged passports?


As I mentioned at the beginning, I really like the Schumer quote about this...

"Sen. Charles Schumer, D-N.Y., also expressed concern. "You [can] have the best computer system in the world, but if the people on the job aren't properly trained and don't execute their job properly, that great computer system will go for naught.""

Yes, training is an important key to security success.

More organizations need to realize this. More resources need to be put towards awareness and training efforts.

CIOs and CISOs need to do better job making the case for information security and privacy training and awareness. As an article this week talks about how information security leaders must maintain metrics to more clearly show to the business executives, who understand metrics better than information security techno-babble, how security training efforts make a difference in the security environment for the business.

Very few security leaders create baseline security metrics and then maintain ongoing metrics to demonstrate the impacts of training and awareness efforts.

Too many business executives and information security leaders believe nonsensical reports, based upon flawed logic, that compares technical apples to training oranges and arrives at the hugely flawed conclusion that awareness and training has no impact on improving information security and privacy.

More information security folks who depend completely upon technical security controls need to understand this.

Yes, I really like Schumer's quote. In fact, I think I'll put it out there again.

""You [can] have the best computer system in the world, but if the people on the job aren't properly trained and don't execute their job properly, that great computer system will go for naught.""

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/426

Comments

A variety of sources indicate that approximately two-thirds of all data breaches are caused by employee error. The other one-third is shared among disgruntled and dishonest employees and break-ins. To me, investing in training sounds like a pretty reasonable thing to do.

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.