Страницы

Showing posts with label Security culture. Show all posts
Showing posts with label Security culture. Show all posts

Wednesday, April 15, 2020

Security culture

toxic security culture in the enterprise industrial pollution hazardous waste caution danger5 signs your security culture is toxic (and 5 ways to fix it)


If a company’s culture is the heart and soul of an organization, then its security culture is its omnipresent guardian.

More than just policies and procedures put in place, a company’s security culture is that “social” operating system that influences and guides employees to integrate security awareness and behaviors into their daily lives. When the security culture starts to break down, whether inside the security team itself or between the security team and the rest of the organization, it can lead to a toxic environment of lax cyber practices, cynicism and finger-pointing.

Industry leaders offer five tell-tale signs that your security culture is toxic, and how to get the security culture you want.

5 signs of a toxic security culture
They’re playing the blame game


When a significant incident happens, the focus in a toxic environment immediately goes to who’s to blame, says Rob Clyde, ISACA board director and past chair who has been involved with ISACA’s annual Cybersecurity Culture Report, due out this fall. The organization looks for a scapegoat – someone to fire. “Look at the average tenure of the leadership. If it’s less than three years, that’s a likely warning sign,” he says...
Security culture

4 Principles That Should Define Your Evolving Security Operations Model


A woman looks at a chart with sticky notes on the wall during a security strategy session.
Maintaining a strong security posture is a dynamic challenge for any organization. It depends on many factors, which can vary over time; companies across the globe are migrating to the cloud to scale more quickly, adopting the latest technology trends to expand the digital footprint and embracing new methodologies such as DevOps to accelerate time to market and address customer expectations.
Yet companies’ operating models are bolted onto an old paradigm that is not delivering the expected value. Although there’s no one-size-fits-all approach to the question of how to best organize the next security operations model, it is often effective to start with a top-down approach involving executives to establish a common aspiration and enable the broader transformation.
The four principles identified below are distilled from the lessons learned during many security transformation journeys.

1. Define Your Goals Clearly

A cybersecurity transformation requires leaders to clearly articulate the goals and principles that are driving it. After aligning all involved parties on these goals, executives can prioritize the work to be done....