0% found this document useful (0 votes)
13 views5 pages

Belief and Culture in Info Security Management

Uploaded by

floydmullings
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views5 pages

Belief and Culture in Info Security Management

Uploaded by

floydmullings
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

The Importance of 1

Running Head: The Importance of Belief & Culture in Information Security Management

TUI UNIVERSITY

Module 2 – Session Long Project

Course #: ITM517

Information Security Overview for Managers and Policy Makers


The Importance of 2

Introduction

Belief guides one's actions. An organization may implement the very best technology as a

means to obtaining information security. However, such approach does not address the root of

the problem. The problem could be engraved in one’s belief – an employee for example, who

believes that he/she was unfairly denied a promotion may react by not taking the necessary

precaution to prevent a virus attack. IT managers should therefore strive to build their awareness

and proper perception of information security and try to create a culture that embraces

information security.

An Overview of the Information Security Issue: Success Training College is a small

community college located in the Bahamas. The college has three different campuses located on

separate islands in the country. The college has approximately 1000 students. In terms of

information technology the institution has two computer labs, one is used as a classroom for the

computer courses and the other lab is made available to the students during the days. There is

also a wireless internet service made available to the students and faculties which can be

accessed while on campus. The main software that is used by the institution is Campus

Anywhere. Campus Anywhere is a software that allows campus PCs and applications to be

securely available to students, staff, and faculty from ‘anywhere’, at anytime. Campus Anywhere

provides 24/7 computer lab access to students from anywhere; it allows faculty and staff to

access it on their own desktop PCs from anywhere. As it relates to technical staffing, the

institution does not have a structured IT department of such. The main IT person is the

institution’s systems administrator who ensures the smooth running of the network and oversees

other systems tasks such as information security. There is also one lab technician who monitors

the activities in the computer labs. All other IT duties are carried out by outsiders.
The Importance of 3

Most of the technologies used by STC are embedded with security features. However,

other than the default security features provided by the technology very little or no emphasis is

placed on beliefs and culture. The institution does not promote a security-centric culture.

Dangers of Ignoring Beliefs and Culture: Information security is more than the

technology. The problem may be rooted in the belief and culture of the individuals in the

organization. Therefore, an IT manager should not ignore such factors when implementing

information security plans. System user’s security awareness should be top priority if proper

security is to be achieved. A college environment like STC has an amalgamation of different user

groups (students, faculty, administration, etc) all having their own beliefs and culture. Such

beliefs and culture will naturally determine their attitude towards information security in the

institution. An administrator for example, may not see the reason she cannot give information

over the phone to someone she thinks she recognize so she disregards the privacy procedures and

give the information anyway. A student for example may not see the reason for not allowing his

“trusted” friend to have his user name and password so they can share account when using the

computer labs, so he disregards the security rules and share his login information anyway. A

faculty member for example, may use the school’s computer to access his/her email and with

little or no precaution he/she downloads an attachment that might be infected with some form of

malware. These are just a few examples of what takes place at the institution on a regular basis

and no technology is able to prevent it from happening. It is a social issue. Such problems can

only be corrected through awareness and proper security perception.

Establishing Awareness and proper Perception: Individuals will always hold what

they believe, however, it is the duty of management to create a security-centric culture in an

organization. Culture is defined as the predominating, shared attitudes, values, goals, behaviors,
The Importance of 4

and practices that characterize the functioning of a group or organization (Fitzgibbons, 2010).

Therefore, cultivating a security-centric culture will curve the users behavior to act properly by

following security polices and procedures. This task however, cannot be achieved solely by the

institution’s technical team. This is a task that will need top management involvement. Top

management has the clout to channel an organization’s culture to a security-centric one.

Management has the power to reprimand, and to reward and such actions should be taken in the

name of promoting a security-centric environment.

Conclusion

According to Mark Seiden, technologies are designed for functionality and not for

security (Seiden 2010). Therefore, an organization should not rely solely on the technology to

meet its security needs. People’s belief and culture will determine the way they perceive their

organizations information security policies and procedures. If they do not believe such

procedures are necessary based on their belief then they will be disregarded which is the

situation with STC. It is therefore important for management to work closely with the technical

team in creating and promoting a security-centric culture. Through such means students, faculty

and administration will develop a better information security perception, allowing them to have a

better appreciation for the institution’s policies and procedures.


The Importance of 5

Reference

Scheiner, B. (2008). The psychology of security. Retrieved January 28, 2010 from

[Link]

Schneier, B (2008). Reconceptualizing security on topics of security feeling, reality and model.

Infosecurity Europe. Retrieved January 2010, from

[Link]

video/[Link]

Seiden, M. “Mark Seiden speech”. Retrieved February 5, 2010 from

[Link]

Fitzgibbons, P. (2010). How to build awareness and change belief and culture? TUI University,

Threaded Discussion. Retrieved February 5, 2010 from

[Link]

Common questions

Powered by AI

Shared attitudes and behaviors greatly influence the effectiveness of information security policies. At STC, diverse individuals hold various beliefs that dictate how they view and apply security policies. If these beliefs dismiss the importance of privacy and data protection, security policies are likely disregarded, reducing their effectiveness. Therefore, a culture fostering shared security values is necessary to align behaviors with desired security outcomes .

A 'security-conscious culture' addresses social issues affecting information security by reshaping attitudes and practices around security policies. The document explains that such a culture involves management actively promoting shared values and goals focused on security awareness. By doing so, behavioral changes are encouraged across all user groups, which helps mitigate risks stemming from negligent or uninformed actions, thereby complementing technological solutions .

Top management's involvement is crucial because they possess the authority to implement and emphasize the importance of a security-centric culture. They can channel resources, enforce policies through reward and reprimand systems, and influence the mindset of the whole organization. This involvement is vital for fostering a shared security perception among all user groups, which technology alone cannot achieve .

The diverse user groups at STC, including students, faculty, and administration, each hold distinct beliefs and practices, complicating the establishment of a cohesive information security culture. These differences lead to varied perceptions and compliance with security policies, creating a challenge for management to implement a uniform approach. The document reinforces the need for tailored awareness and education initiatives to align these disparate groups under a unified security framework .

Belief and cultural background significantly impact information security because they shape how individuals perceive and follow security practices. At STC, for instance, students, faculty, and administration have different beliefs which influence their behavior towards information security. A student's belief in trusting a friend may lead to sharing login credentials, or a faculty member's casual attitude towards email attachments might result in malware infections. This indicates that security issues are not merely technical but deeply rooted in the users' cultural perspectives, necessitating management's role in promoting a security-centric culture .

While technology is crucial for providing functionality and baseline security, it is inadequate alone because it cannot address the human element of security breaches. Technologies, though designed with security features, are often bypassed due to the users’ beliefs and cultural tendencies, as illustrated by numerous security lapses at STC due to human errors. Thus, technology must be complemented with a security-conscious culture to be effective .

The lack of a dedicated IT department at STC poses significant risks to its information security objectives by limiting focused oversight and rapid response capabilities to security threats. The document suggests that this absence can result in a disconnection between technology management and strategic security practices because external personnel may not fully grasp or align with the institution’s unique security needs or cultural intricacies. This gap can endanger the institution's ability to maintain effective security protocols continuously .

Behavior change is critical in information security management, as illustrated by STC's example, where human factors, rather than technology, are often the weak link. Security breaches, such as sharing passwords or failing to follow privacy procedures, stem from ingrained behaviors and beliefs. Hence, effectively changing these behaviors through awareness and education is vital for improving security perceptions and compliance with security policies within the institution .

STC has limited technical staffing, relying on a systems administrator and a lab technician, with other duties performed by external personnel. This setup may constrain its capacity to enforce robust information security policies and nurture a security-centric culture. Limited internal staffing can lead to insufficient internal security oversight and awareness programs, essential elements for effective information security management in an institution with diverse user beliefs .

Management cannot achieve a security-centric culture alone as it requires the involvement of all stakeholders. Evidence from the document notes that creating such a culture necessitates collaboration with the technical team and active participation from every level of the organization. Both management and technical staff must work together to educate and transform the beliefs and practices of users to support security initiatives effectively .

You might also like