The Macrosite for News, Analysis and Opinion about the Future of the Internet
Mansur Hasib

For Better Enterprise Security, Give Users More Control

Written by Mansur Hasib
8/20/2012 26 comments
no ratings
DISCUSS     Email This

Are users in your organization fully empowered to utilize their computers -- install and update software, define printers, and perform other routine tasks? Or do they have to call the help desk for every little thing they need done, frequently waiting several days only to be told, "No, we cannot do it" or "It will compromise security" or "It's just not allowed in our organization"?

Having worked in both types of organizations, and having managed the IT environment in an empowered organization as CIO/CISO, I have observed that users in the second type of organization have an antagonistic relationship with IT and information security. They feel security is someone else's responsibility. Experimentation and innovation are low. IT is usually overworked and understaffed and does not enjoy fulfilling the majority of requests, since they are routine and present no new challenges. The typical call volume for service is also very high.

In the empowered organization, users are more conscious of and more engaged in security. There is a collaborative relationship with IT, which is viewed as helpful. Users also recognize and accept information security as their responsibility.

Organizational information security rests on three pillars: technology, policy, and people. Getting the people part right is very important for any organization. Getting it wrong could hurt the organization in many ways. Users could intentionally bypass security measures they do not view as helpful. They could fail to disclose problems or share concerns. They could suppress important ideas and suggestions that could improve the security of the environment.

During a keynote address at a recent CISO Executive Summit in Washington, DC, Ira Winkler, CEO of Internet Security Advisors Group, told CISOs to create a collaborative relationship with users to keep IT from being labeled as the "Department of No." Justin Somaini, CISO of Yahoo, shared similar experiences during an afternoon keynote. He argued that it was important to get users within the organization to accept information security as their personal responsibility. One key way to accomplish this, he said, is to empower users.

Somaini found very little difference in security between empowered and non-empowered environments. But in my own experience, I have observed more virus infections and security issues in organizations with severe restrictions on user capabilities, primarily because the absence of a security culture promoted unsafe user behavior.

The remarks by Winkler and Somaini made me think of the safety culture I observed at a nuclear power plant early in my career. The organization was run according to key values such as safety, employee empowerment (with a questioning attitude), teamwork, customer service, excellence, and diversity. These values were consciously driven throughout the organization. All employees were empowered to question any order they believed would reduce safety. Supervisors could not penalize employees for such questioning. Everyone was encouraged to think continuously of ways to improve safety. Thus, germination of grassroots ideas from people closest to the work was part of the culture. This produced a highly safety-conscious workforce, superior team spirit, a collaborative relationship between workers and management -- and an excellent safety record.

The same principles could achieve a culture of information security within an organization. After all, information security isn't much different from safety.

Granted, in a few highly controlled, top-security environments, empowerment may not be appropriate. Users who work in these environments easily recognize and appreciate the restrictions. However, most enterprises would benefit greatly if a culture of security were cultivated throughout the organization. User empowerment and the cultivation of a collaborative relationship between IT and the user community may be the key ways to foster such a culture.

Related posts:

— Mansur Hasib has served in CIO/CISO and other leadership roles in the public, private, and education sectors.

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 3   Next >
Mitch Wagner
Thinkernetter
Monday August 27, 2012 1:05:17 PM
no ratings

Yup. If IT makes it harder for people to do their jobs, then people will find a way around IT. 

slfisher
Thinkernetter
Sunday August 26, 2012 3:01:14 PM
no ratings

Read through all the comments only to find you'd said in the first one what I'd planned to say. :) but yes. I'm already hearing stories about that now, that people who want to use the Internet for a small amount of personal use are told they can't, but instead ot not using it, it simply means they bring in tablets and smartphones and do it that way. Similarly, they're told they can't work at home -- so instead they do so in an insecure fashion that results in versioning problems as well.

syedzunair
IQ Crew
Thursday August 23, 2012 9:33:46 AM
no ratings

Nimantha, 

Yes, the company would be able to track employees but would the IT department want to be on the hunt always? I mean that the IT could be more productive if they were to empower the users rather than only being a watchdog and penalizing the employees who do not follow rules. 

AllieEvans
Rank: Cave Painter
Thursday August 23, 2012 6:36:23 AM
no ratings

It sounds to me like you're only option would be to find a way to use a different network. I hate to say it but like a cellular one.Perhaps someone else has some nifty ideas for you, but if the ATV cannot connect to the enterprise level network, you're SOL. You could check the jailbreak forums and see if there are hacks to enable this. software patents

nimantha.de
IQ Crew
Thursday August 23, 2012 2:24:17 AM
no ratings

Yes Syed you have a good point where users might try out things which have been locked out from them but I feel that by doing that the company will be able to track down who are trying bypass company rules and regulations and take strict action against them.

walkerkevin164
Rank: Cave Painter
Wednesday August 22, 2012 11:13:26 PM
no ratings

tnx really helps

mhhfive
IQ Crew
Wednesday August 22, 2012 6:37:38 PM
no ratings

Perhaps there should be designated "insecure" systems for printers .. with an "air gap" between the network that should be secure.

Basically, set up a separate network for "casual use" -- but I suppose that could backfire b/c then ppl get too comfortable with the easy to use network.

Mansur Hasib
Thinkernetter
Wednesday August 22, 2012 5:29:48 PM
no ratings

The concept many security strategists are thinking about is the conscious promotion of a security culture throughout the organization.  Yes the idea of rewards can enter into this.  But the rewards do not have to be monetary -- badges of honor -- the concept of gamification and the concept of enterprise social networking can be used effectively to engage everyone even in a very large enterprise.  The nuclear power plant where I had observed safety as a culture used to give out certificates, sweatshirts, and name recognition for safety ideas and improvements in safety.  Security was always everyone's responsibility -- so it is not a new responsibility we are giving users.  Great contributions everyone.  Thanks.

Mansur Hasib
Thinkernetter
Wednesday August 22, 2012 5:18:40 PM
no ratings

@rdv - Security and social networking in the enterprise is quite an extensive discussion. In short, an enterprise must consciously develop internal and external  social network environment strategies and associated security policies ensuring that enterprise intellectual capital is protected.

lennox-brown
Rank: Cave Painter
Wednesday August 22, 2012 5:09:14 PM
no ratings

The "collaborative relationship between IT security and users" is a desirable state, but how is this achieved?  The bottom line is that in any relationship, there is the question of benefit.  How the user see the benefit to him/her will determine the success of the relationship.

Will support of the relationship result is less/no negative sanctions or more "real" positive benefits?

It is my experience that failure to support security policy results in negative sanctions (aka - unplanned career moves). Support of security policies by users are not normally followed by "real" positive benefits to the user.

Maybe it's time to incentivize user support for security with monetary incentives, such as bonuses, stock options etc. We reward employees based on productivity and profits, why can't this be done for IT?IS security in for profit organization. Admittedly, the rewards may have to be appropriately crafted for government and non-profit enterprises.

For this to work, you will have to establish metrics for the organization security posture and base the monetary/financial incentives on annual security related measurements. Radical? Yes, but it will be interesting to see the results.

Page 1 of 3   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Mansur Hasib
Mansur Hasib
Mansur Hasib   6/11/2013   20 comments
The publishing world has long been controlled by powerful companies with high costs, barriers to access, restrictions on distribution, one-sided copyright ownership contracts, and lengthy delays in getting critical information and knowledge out to a broad audience. In this world it often seemed all but the most famous of authors controlled little while publishers controlled everything. In the academic community, the sad result has been an excessive price increase in the cost of textbooks. Technology is finally empowering authors.
Mansur Hasib
Mansur Hasib   5/10/2013   49 comments
In all my years interacting with CFOs, I have not met one who actually understood IT -- not that I expected them to. Why, then, do I continue to see ads seeking a strategic CIO who will report to the VP of Administration and Finance or the CFO? Sometimes ads are slightly better: CIOs report to the Chief Operating Officer. Those conducting the recruitment will sagely say: “The CIO will have complete empowerment and access to all cabinet members and the president.” However, these organizations appear to lack an understanding of the role of the CIO and the CFO.
Mansur Hasib
Mansur Hasib   5/2/2013   2 comments
After observing and writing about CEOs who do not leverage their CIOs to propel their organizations forward, it was very refreshing to learn about the great CEO/CIO partnership at Kaiser Permanente at this year’s World Health Congress held in Maryland.
Mansur Hasib
Mansur Hasib   4/22/2013   20 comments
Despite an initial round of federal funding to develop state health information exchanges (HIEs) as part of Obamacare, these clearinghouses were challenged to develop a financially sustainable model. Because it addressed sustainability early, the Delaware Health Information Network is viewed by many as a template for HIE success.
Mansur Hasib
Mansur Hasib   4/9/2013   15 comments
It began as a relaxing visit with my college buddy and his family. It became a glimpse into the technology-enabled future of worldwide collaboration in engineering.
5
of
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Mitch Wagner
'Digital Nomads' Work From Anywhere & Everywhere

2|14|13   |   2:35   |   20 comments


New tools like laptops, tablets, smartphone, and wireless connectivity let us work from San Diego to Katmandu, and anywhere in between. But time management remains a problem.
Second Shooter
It's Not Tablets That Threaten the PC

2|13|13   |   2:21   |   8 comments


Blaming the PC's gloomy future on tablets is an oversimplification.
Reiter's Block
New Mobile Tech Lets Employees Do More With Less Power

1|8|13   |   3:04   |   8 comments


With the huge number of mobile devices available, IT departments need to consider how much computing power employees need, and in what form.
Mary E. Shacklett
Financial Services Policies Lag Tech Advances

12|4|12   |   2:18   |   6 comments


Regulations haven't kept up with advances in mobile devices and credit cards.
Wisdom of the Big Chair
Price, Not Features, Driving Smartphone Sales

11|29|12   |   2:01   |   7 comments


A survey by JD Powers found that customer interest in product features is lessening as phones evolve. Rather than features, price is driving purchases, and that change could have a dramatic impact on how IT departments secure these devices.
Second Shooter
Tablet WiFi Getting Away From Us

11|9|12   |   2:08   |   2 comments


The iPad Mini is the latest iteration of the exploding tablet category. Because most tablets are WiFi-only, they create a new kind of mobile network. The problem is that we don't have issues like roaming and security defined for this new world.
Mitch Wagner
Confessions of a BYOD Hypocrite

11|8|12   |   2:35   |   No comments


BYOD is a bad idea, yet even a dedicated opponent finds it inescapable.
Wisdom of the Big Chair
FBI Turns Attention to Mobile Security

10|30|12   |   3:45   |   8 comments


The FBI recently issued a warning to smartphone users, highlighting two mobile malware applications: Loozfan, which steals personal information, and FinFisher, which is spyware that takes over a smartphone's functions.
Second Shooter
What Microsoft Is Betting On With Windows 8

10|22|12   |   2:12   |   13 comments


Intel's numbers say the PC is at risk, and Microsoft's Windows 8 interface is an attempt to make Windows relevant in the tablet age. But Microsoft could be betting too much. A dramatic transformation to cloud-and-appliance would mean a big change for our industry.
IETV: the thinkerNet on film
5
of
John Kennedy
How Big-Data Is Changing Marketing

6|13|13   |   1:07   |   1 comment


Big-data and analytics tools enable marketers to understand customers as individuals, identifying unmet needs and addressing each customer as a "segment of one," says John Kennedy, VP corporate marketing, IBM.
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   10 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   1 comment


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
2pm EDT
Fri
Jun 21st
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   6/18/2013   Post a comment
The IBM Smarter Commerce Global Summit in Monaco kicked into high gear today, and we've already begun to see news emerging from that lovely city-state by the sea.
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
NSA Leaks Shine Spotlight on Perils of Contractor Partnerships
Jason Mick
The US National Security Agency learned the
hard way that it can be dangerous to give a contractor too much money and access, with too little scrutiny. The NSA and other government agencies hire tens of thousands of contractors a year to analyze data. Edward Snowden -- who revealed himself as the NSA leaker after fleeing the country -- was one such contractor, reportedly holding a $122,000 salaried position at Booz Allen Hamilton at the time of his departure.

CLICK FOR MORE