Opinions are those of the author and do not agency. · Opinions are those of the author and do not...

13

Transcript of Opinions are those of the author and do not agency. · Opinions are those of the author and do not...

Page 1: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer
Page 2: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding

agency.

My Thoughts - Disclaimer

Page 3: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

Parent InstitutionExternal InstitutionsFunding AgenciesSenior ManagementPIs and managersCybersecurity TeamInfrastructure AdminsCode developersWeb designersDesktop Admins

Stakeholders

Helpdesk StaffPublic Relations DeptLegal DeptHuman Resources DepttIT StaffInternal - end-user (by function)External - end-user (by function)Contractors/sub-contractorsAnonymous

Page 4: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

● Security Awareness● You Are The Target● Social Engineering● Email and Instant

Messaging● Using Your Browser

Safely● Passwords

● Encryption/Data Protection

● Mobile Devices● Protect Your Computer● Wi-Fi Security● Social Networking● Reporting a Security

Incident

Typical Topic Areas

Page 5: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

● Too many topics● Too much information● Infrequent delivery● Not relevant to daily tasks● Poor practices● No management backing● No consequence for poor security

Why Do We Fail?

Page 6: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

● Select only a few topics at a time● Concentrate on indicators of danger● Continuous w/ periodic check-ups● Tailor message to the audience● Practice what you tell others to do● Ensure management understands● Obtain support for consequences

How Do We Succeed?

Page 7: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

Shameless plug ….

Remember ...

Page 8: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

CTSC Provides Training for CI Professionals

Page 9: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

Contact: Jim Marsteller for more information

[email protected]

The slide deck covers the “typical topics”

https://docs.google.com/presentation/d/1bS19nStvQOODmH-PqW8Lro0n49H3L__o2EhfHrY08Go

CTSC has Slides for End-User Training

Page 10: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

●●●

●●

CTSC Guide Template - Acceptable Use Policy

Page 11: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

●●

CTSC Guide Template - Incident Response Policy

Page 12: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

●●● …●

A Note About Privacy Policies ...

Page 13: Opinions are those of the author and do not agency. · Opinions are those of the author and do not necessarily reflect a position of CTSC or any funding agency. My Thoughts - Disclaimer

We thank the National Science Foundation (grant 1234408) for supporting our work.

The views and conclusions contained herein are those of the author and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied, of the NSF.

Thank You!