Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Sprint Communications for Continuity of Operations
Oracle Resource Center
NEW! Priority Report: Virtualization
GSA: Your Customer Service Agency
Government Leadership Survey
Green Solutions Guide
Report: Information Sharing
DISA IT Strategy & Vision
Emergency Preparedness Report
Report: Green Computing
PEO EIS Guidebook
Content Library

More >>



Latest News
ADVERTISEMENT





 

Workers tested on security smarts

Agency officials explore ways to make employee security training effective

By Mary Mosquera
Published on September 17, 2007

Comment

Click here to comment on this article


Related story links

Survey: CISOs worried about mobile data security

IRS employees fall for faux password scam

For VA, all security is local


Newsletters

You might also be interested in these FCW newsletters:

Daily
Management

To learn more, click here.


8 security awareness tips from FTC

Here are eight ways the Federal Trade Commission raises security awareness among its employees.

  1. Holds an agencywide Privacy Week with seminars, activities and contests designed to increase awareness of privacy policies and requirements.

  2. Creates education campaigns about important topics, such as laptop PC security and data breach notification.

  3. Sends weekly e-mail messages to remind employees of policies on privacy and data security.

  4. Has a privacy resources Web page on the agency’s intranet.

  5. Presents panels and presentations on privacy.

  6. Publishes monthly and quarterly newsletters on privacy-related topics.

  7. Has specialized, role-based training for specific groups, such as student interns.

  8. Requires the chief privacy officer to attend the meetings of different organizations within the agency.


— Mary Mosquera


Agencies have implemented technology policies and procedures to safeguard data and system security. However, the toughest part is getting employees to follow them and change the way they handle data, security experts say.

Agencies require annual security awareness training, but it is difficult to determine how effective it is and whether employees protect data in their daily work, said Marc Groman, chief privacy officer at the Federal Trade Commission. A formal training program should include one or more computer-based training modules or live presentations that cover basic computer security concepts, he said. Privacy and data-security education and training must be offered year-round, Groman said, adding that “it’s not a one time exercise, program or event.”

One way to measure progress is to track how many agency employees and contractors have completed such training, security officials said. For example, at the Justice Department some agencies block the network accounts of employees who have not taken security training classes by a certain date.

Required training should be the start, not the end, of an effective employee-training program, Groman said. “There must be other creative, ongoing initiatives to keep privacy and data security in the minds of your staff on a daily basis,” he said. FTC keeps data security and privacy on the front burner by offering a number of programs throughout the year.

At Justice, officials annually revise the department’s security training topics, which are closely related to rules that employees must agree to follow when they use departmental systems. The topics evolve as awareness of specific problems grows. Last year, for example, the increased occurrence of data breaches led to expanded training related to safeguarding personal information.

Some agencies are trying different approaches to assess how well employees respond to suspicious situations. This year, Justice tested a program in which it sent a phishing e-mail message to a number of employees. Because the sender was unknown, employees were expected to be suspicious and not open the attachment. If an employee opened the attachment — activity that training should have taught employees not to do — the department notified the employee that opening the attachment was risky behavior and warned the employee not to do it.

“We can get feedback on how effective it is at changing that behavior over time,” said Dennis Heretick, Justice’s chief information security officer.

Justice officials say they hope to expand the phishing exercise, conduct periodic random sampling and keep statistics to determine if fewer people fall for phishing scams.

The Treasury Inspector General for Tax Administration recently conducted a similar hands-on exercise. TIGTA staff members, posing as computer help-desk representatives, called Internal Revenue Service employees, requested their user names and asked them to temporarily change their password to one the TIGTA staff members suggested. About 60 percent of those sampled did so.

In response to the TIGTA report, the IRS plans develop awareness programs for employees about social-engineering attempts by hackers, said Daniel Galik, associate chief information officer for cybersecurity at the IRS.

Agencies can monitor employees’ compliance in other ways, such as conducting internal audits of privacy controls, experts say. For example, an agency can make visual spot-checks in offices and common area file rooms to verify that office doors have working locks and that personal information is not in plain view on unoccupied desks.



upcoming event

Enterprise Architecture 2008 - Washington, DC
September 9 - September 10, 2008

Occupational Health & Safety Executive Summit - Arlington, VA
October 6 - October 7, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email