Information Assurance: Managing Organizational IT Security Risks

Recognize various types of information system users
Describe examples of rules of behavior
Understand security issues associated with general users
Understand the insider threat associated with privileged users
A fairly comprehensive checklist is provided in the Appendix of this book as a mnemonic for the IA practitioner. Anyone can follow a checklist to secure a system. The real challenge is obtaining (and maintaining) a level of system security while it is managed, maintained, and used by people.
The good news is that a successful IA program depends upon the involvement and cooperation of people. The bad news is that a successful IA program depends upon the involvement and cooperation of people. These people come with varying backgrounds, experience, skill levels, and capabilities; unique personal issues; and even different moral values. The challenge for the organization is to take all these uniquenesses and channel them into a cohesive team that works together to achieve common objectives. It is sometimes likened to herding cats.
An effective security training and awareness program is essential to ensuring that the organization's IA policies and procedures are understood. You can't expect people to follow rules when you do not first explain what those rules are. This training should be relevant and tailored to the various roles that people take in regard to the use of information systems.
All personnel with any level of access to the computing environment fall under the category of "general...