<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MWJ Computing &#187; InfoSec</title>
	<atom:link href="http://www.mwjcomputing.com/blog/category/infosec/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mwjcomputing.com/blog</link>
	<description>A life lived through digital exploration.</description>
	<lastBuildDate>Mon, 02 Aug 2010 16:56:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Why users don&#8217;t get security policy</title>
		<link>http://www.mwjcomputing.com/blog/2009/12/why-users-dont-get-security-policy/</link>
		<comments>http://www.mwjcomputing.com/blog/2009/12/why-users-dont-get-security-policy/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 02:32:23 +0000</pubDate>
		<dc:creator>Matt Johnson</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[Random Thoughts]]></category>

		<guid isPermaLink="false">http://www.mwjcomputing.com/blog/2009/12/why-users-dont-get-security-policy/</guid>
		<description><![CDATA[I have been thinking about this for a long time. I still may be a fledgling in the Information Security community, but feel that I have a pretty good grounding in the InfoSec concepts. So here it goes…. Users don’t get security policy because the don’t feel it directly relates to them. Users may wonder [...]]]></description>
			<content:encoded><![CDATA[<p>I have been thinking about this for a long time. I still may be a fledgling in the Information Security community, but feel that I have a pretty good grounding in the InfoSec concepts. So here it goes….</p>
<p>Users don’t get security policy because the don’t feel it directly relates to them. Users may wonder why would a removable media or email policy apply to them? I don’t really blame users for feeling this way. Most people are genuinely honest people trying to make a honest living. They are not trying to steal data or cause a data breach. I will go far as to say that the majority of data breaches were not the result of some willful action to release or steal the data. </p>
<p>I remember when I was just a user and I laughed at some of the of the policies thinking who would do that? It wasn’t until later I realized policies really are trying to catch the exception to the rule not the rule itself. I don’t feel that this is adequately communicated to most users. If we were to educate users that policies were there to help them do their job not to control or dominate them users may be more willing to accept policy. An analogy that I think could work is Monopoly. A normal game of Monopoly has rules and people police other players when it comes to rules. People normally are happy when it comes to playing within the rules and expect it while still enjoying the game. Why can’t this translate to security policy? </p>
<p>This however assumes is that everyone plays by the rules equally. If you are a user in the mail room or someone in a CXO position, everyone needs to follow the rules and help police everyone. No one, no matter who they are, is treated different. This sadly isn’t always the case.</p>
<p>Until the individual user experiences a negative effect of someone not playing by the rules, or policy, people don’t understand why the should care. I think if we spend more time thinking like users and educating them to why it is an advantage to them to follow the “rules” we might find our workplaces or organizations a more secure place.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mwjcomputing.com/blog/2009/12/why-users-dont-get-security-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
