preview

The Individual Employee With The Working Knowledge Associated With Their Work Environment

Decent Essays

Arming the individual employee with the working knowledge associated with their work environment goes a long way in terms of supporting information security. As an example, users during the course of employment will be exposed to confidential information. In efforts or reduce the risk of leaks associated with such content the organization must require all employees sign a confidentiality agreement if the company expects the data to not become public knowledge. Issues tied to printed works are just one example of the requirement regarding policy generation. Moreover, users must be aware that their actions on the organization 's information system are continually monitored, because without such knowledge In addition to combating …show more content…

However, without the backing and adherence from senior level management policy creation becomes a box checking event to pass audits. In addition, receiving buy-in from users, to include senior management, must understand the consequences associated with the failures to abide by the company’s policy, and levying the consequence to all employees equally and justly. Lastly, users must understand why policies and procedures are in place. Without understanding, user’s behavior will ultimately put the company in a defensive position.
Policy Buy-In
For an organization to run smoothly, organizations must utilize polies and procedures. Furthermore, to ensure a smooth operation those policies and procedures must be enforced. Unfortunately, one of the most difficult aspects of ensuing policies are effective within the organization is through policy enforcement. Users themselves have the ability stress the boundaries of policy guidelines. There are those within an organization who at times have a problem with the policies within the organization who dislike guidelines before them to include top performers. However, an equal treatment from management is important if the organization is to assure users throughout organizations understand the enforcement of organizational policy will levied equally to all individuals. However, security professionals will are not able to reach the point of enforcement if the policy presented to the executive

Get Access