Opinion: Four good reasons for Security to talk to HR
More In Security
- Not where you think they are
- When disaster recovery's down to you
- At the airport, an ID theft takes flight
- Goodbye to the Year of the Fire Pig
- Mixing open- and closed-source, managing risk
- Privacy and piracy: What are we telling the kids?
- Security and the One Laptop Per Child sensibility
- Ghosts in the machine, spooks on the wire
- Find them and fire them: 5 steps
- Hard times on the HIPAA front
- You don't want to hear it: 10 pieces of lousy security advice
- Oh, don't tell me: 10 claims that scare security pros
By confusing this topic, loopholes are created where people may claim that only specific behaviors were proscribed, or that there wasn't any clear connection between misuse of technology and an actual ethical violation for which one might be terminated. Confusion creates uncertainty, and uncertainty lets misbehaving people through the cracks -- even when the violations are pretty egregious.
It's important to work with HR to understand the ethics standards for the organization, and to make sure that they account for the things that might take place. For example, a non-IT ethics policy might focus on job performance and gender sensitivity but ignore the resources and common behaviors permitted by the presence of information technology.
By reviewing the policies together, HR may decide to add specific topics about handling sensitive information or behaviors while connected to company resources. With a little attention, it may be possible to lean on the HR ethics policy heavily so that an Acceptable Use Policy can focus on real use and potential pitfalls -- instead of trying to re-state the ethical justification behind the policy.
Training vs. awareness
There aren't enough hours in the day for most IT security staffers, so I often wonder why they spend any of them offering information-security training sessions for the general office population. Not only is it wasteful to put on single-purpose training sessions of that sort, but those most likely to attend voluntarily are not those who most need to be reached.
Whether selling items on eBay or running a business from one's desk, the behaviors, prohibitions, policies and training ought to be the same regardless of mode. Trading ID badges and database accounts? Leaving keys in the door or writing a laptop's password on the cover with a marker? Calling a manager when something is seriously amiss in a system or paper files are found unlocked and rifled-through? Technology is not the issue.
Like most other controls in information security, the most effective ones are indistinguishable from properly performed business processes, so there's little good reason not to combine security training with periodic HR training on organizational policies. As a first step, IT security trainers should pick up the HR training list or catalog and see where the information can be combined in existing courses.
"Awareness," on the other hand, is typically used to mean ongoing reminders about right actions and proper behavior -- distinct from classes or instructional sessions that constitute formal training. A security awareness program is a good vehicle for ensuring that good behaviors are maintained, through messages, posters, periodic campaigns or other ways of getting short messages out. However, the effectiveness of awareness programs is often not verifiable, so they're poor tools for communicating important changes or events.
jon espenschied
Additional Resources



White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

