What's changed: Initial version
5.3Security Education, Training, and Rule Operation
Learn, through concrete organizational scenarios, how to design employee education, run and evaluate targeted-attack drills, thoroughly communicate rules and procedures, handle onboarding/offboarding procedures (account issuance and privilege revocation), respond to rule violations, and raise organization-wide security awareness.
No matter how many technical countermeasures are stacked up, it is people who ultimately operate the systems. Opening a phishing email, taking confidential information out on a personal USB drive without knowing the rules, leaving a departed employee's account untouched--incidents rooted in "people and operations" never stop occurring. An information security manager must design a mechanism that not only creates rules but embeds them across the organization and continuously verifies them.
5.3.1Employee education and targeted-attack drills
- Employee education matters most when it is not a one-time session at hiring but is repeated on a regular basis (roughly once a year or more). Rather than sticking to general lectures, covering cases that have actually happened (or could happen) at the company itself makes it easier for employees to feel personally implicated. The effectiveness of the education should be measured not just by attendance rate but by the pass rate on a comprehension test and the trend in the drill "click rate" described below.
- A targeted-attack drill involves sending employees a simulated attack email (disguised as a fake invoice, a fake HR notice, and so on) and measuring the open rate, link-click rate, and attachment-execution rate. The goal is not to single out and punish specific employees but to understand where the organization as a whole is vulnerable and feed that back into improving the education content. Giving employees who fall for it immediate feedback, such as displaying an awareness-raising message on the spot, tends to make the lesson stick.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

