preview

Defining Our Security Education Program

Decent Essays

Defining our Security Education Program

Information Security education initiatives are vital for Information Security group’s effort to be a successful partner within the company culture. Establishing a formal program that articulates our strategy and approach with respect to security education as the Information Security Education Program (ISEP) will be the first step towards effectively providing and measuring successful behavior change metrics in our goal to create a culture of security here at company. This will allow us to better understand requirements, identify gaps, and focus on initiatives to be able to better plan resource allocation and needs, assemble our team, and utilize our branding (email templates, …show more content…

It is crucial for the success of this program to define our initiatives and ourselves as in support of and in collaboration with communications stakeholders.

With minimal resources to execute the program it will be important to build strong relationships, engage influencers, and nurture those connections. The team will consist mostly of identified IT leaders from all BU’s and segments, as well as volunteer employees worldwide who have a passion for security. The global team would help to identify the program’s worldwide goals, and then introduce initiatives on a local, regional basis, allocating communication andd local resources as needed. All local initiatives follow the agreed upon existing global branding, to help ensure a consistent, coherent look and feel for all security deliverables. (Get yourself a logo and make it your brand with consistent recognizable fonts/messages).
Foundational Activities - Assessing your culture

Most security risks result from human behavior. Our cast members & employees take unsafe measures to save time and effort, and may lack awareness about the security risk involved.
An information security cultural assessment will be required to implement the program. Its purpose is to identify any unknown security risks threatening the Disney environment. Implementing a re-occurring information security cultural assessment and using interviews and focus groups, we will ask each group of employees the following questions:
• What do

Get Access