Writers' Community!
Home News Business Science & Technology Life
Front Page Page Two Columnists Submit an Article FAQs Contact Author Login
Article Submission
We Need YOUR Articles!
We'll Promote Them for FREE!

Author Login

New Authors
Register Here


Now Serving 5,553 Authors
48,417 Quality Articles
& 3,664 Current Users Online!
Featured Authors
Robert Melaccio, Sr. (6,499)
Richard Nicastro (2,545)
Dianne Lehmann (3,112)
Mike Fak (6,887)
David Pekrul (710)
Terry Mitchell (2,785)
Sara O'Rourke (401)
Joel Hendon (4,850)
Susan Thom (9,014)
Laura Trahan (32,713)
Abigail Richards (6,393)
Peggy Butler (3,553)
Avis Ward (13,445)
Tex Norman (4,329)

View All Featured Authors
Most Recent
Are You Still Using a Dirty, Unorganized Computer?

Cisco Training

Top Five Networking IT Training Certifications

Getting Connected with the Help of Routers

To Prevent A Data Recovery by Cooling Your Hard Drive

10 Things To Love About the Iphone

10 Things To Hate About the Iphone

Emerging Technologies and Their Impact on Society

Data Recovery Hard Drive Do's And Don'ts

Does a Microsoft Registry Cleaner Remove Spyware and Malware?

Home » Categories » Computers & Networking » Other Computers & Networking » Proposing an Information Security Awareness Program » Printer Friendly

Claudio LoCicero

Proposing an Information Security Awareness Program

Rated 3.5 out of 5
No Reader Ratings Available ?
Rate It  /  View Comments  /  View All Articles submitted by Claudio LoCicero
Submitted Thursday, September 20, 2007
Claudio LoCicero (183)
Claudio LoCicero


Log in to become a member of Claudio LoCicero's Fan Club!


Risks to confidentiality, integrity, and availability of organizational information assets are constant, yet evolve on a daily basis. Individuals need to be informed and prepared for information security threats directed towards them, their computers, and ultimately their way of life. These threats take on many forms, but they all fit in certain established and identifiable categories. An individual’s ability to distinguish between benign incidents and an actual information security threat or risk rests on the breadth and depth of security awareness training they have received.

Proposing that an Information Security Awareness Program be developed for the employees of your organization to educate them on the information security risks they face while utilizing organizational information assets, and by extension, their personal information is a wise move for IT executives to make. The awareness program can be developed in conjunction with the implementation of an overall IT Governance methodology such as COBIT or as a standalone program depending on the IT maturity level of your organization.

Firewalls, intrusion detection, and intrusion prevention systems, although a requirement for today’s network, can not completely defend an organization from current security threats. Organizations need to ensure that their employees, vendors, partners, and subcontractors will not leave the organization vulnerable to various risks such as operational disruptions, loss of valuable informational assets, public embarrassment, or legal liability due to a lack of information security awareness.

There is not only a clear need from a practical standpoint to ensure individuals receive adequate and properly funded training in the protection of organizational and personal information assets, but depending on your organization’s industry there may also be regulatory requirements such as HIPAA and SOX to do so. The development and implementation of an information security awareness program should encompass a mandatory annual refresher component to ensure the promotion of a security aware culture among employees.

Information security has become a key concern among information technology professionals and that concern, when shared by management, will benefit organizations as a whole. Top-down management support is crucial for the survival of the program and its goal of creating a culture of information security awareness within the organization. The program would also be a valuable component of showing that executive management is performing due diligence in securing organizational information assets.


Written by Claudio LoCicero, M.S.

Over his career he has held several technical and management positions both in the United States and overseas within the private and government sectors.  Claudio LoCicero holds a Master of Science in Information Technology with an Information Security Specialization.  He also holds numerous professional certifications such as the PMP, CISM, CISSP, ITILF, along with several certifications from Cisco, Microsoft, and the NSA.






Reprint Rights

Log in to become a member of Claudio LoCicero's Fan Club!

Comments on this article:
No comments yet.


Was this article helpful to you? Leave a Public Comment or Question:

 

This Article has been viewed 12 times.
Article added to SearchWarp.com on Thursday, September 20, 2007
View other articles written by Claudio LoCicero (183)
Claudio LoCicero


If you found this article interesting, you may want to check out:

Disclaimer:  All information on this site is provided for informational purposes only! By no means is any information presented herein intended to substitute for the advice provided to you by any health care or other professional or organization.


Today's Most Popular
How to Configure an NTP Network Time Server in Windows XP

Building a NTP Server

Weird Tattoo Effect (Photoshop Tutorial)

How to Create a Mirror Image of Your Hard Drive

Setting up a Windows Time Server

Learning to Type with Typing Games is Child's Play!

Step By Step Instructions On How to Install a Printer Without the CD

Microsoft Registry Cleaners - are Vista Certified Cleaners Best?

Using VOIP with Your Cell Phone

How to Configure a Windows 2003 Time Server

Home  |  Page Two  |  FAQ's  |  Contact  |  Terms of Service  |  Article Submission Guidelines  |  Writers' Contests  |  Privacy  |  Mission / About
Copyright © 1999-2008 SearchWarp.com, All Rights Reserved - SearchWarp.com is an IcoLogic, Inc. Company