Perimeter
7/9/2012
11:54 AM
50%
50%

Being Compliant Is Not Only Training And Rules, It's Culture

Too many organizations teach compliance instead of live it

In high school, we all took the basics: language, math, and science. Now that a few years have passed (OK, more than a few for some of us), who could pass the final exams in those classes right now? Probably very few. Education fades from our memory unless regularly reinforced. But education and training alone are not enough. The habits we develop determine and drive what we are good at.

Just like individuals, organizations have habits as well -- cultural habits. Ever go to a restaurant with several horrible waiters? Odds are there were no great waiters in the place; the standard of service is simply not very high. It is likely that great waiters who happen to get hired will eventually either leave or become lazy waiters themselves.

If your colleagues are slack about security and compliance, then you are more likely to be slack about it as well. You may even be encouraged to be slack: “Hey, don’t spend time documenting that security process right now. We all know our data is safe, and I need your help on this other deadline.”

Maybe the data is safe that particular day. But what about the future, when months and months of skipped documentation leads to lost knowledge? Time passes, systems change, and staff leaves. Without regular reinforcement, the “things we all know” become a collection of “things we used to know.” Infrequent training alone can never fill this gap. Even frequent training, if not reinforced by your company culture, will be pointless.

As social creatures, most of us want to “just get along.” We can be conflict-averse and prefer to keep a low profile instead of speaking up for important processes if they are contrary to the work culture. After all, who wants to be a tattletale in a noncompliant culture?

I find restaurants with great wait staffs clearly spend a lot of time, and therefore money and time, training their staffs. But they also make a point to only keep staff that fits the culture of excellence. (If you damage our service reputation, then you can’t stay.) As time passes, the culture of service is ingrained and normal, not just an overhyped lesson from sporadic class instruction.

Likewise, I see great business organizations operating the same way. Training and rules are not the be-all, end-all for security and compliance. Rather, training and rules are used to provide the framework and support for excellence. Skimping on security and compliance efforts does more than break rules; it breaks cultural norms.

Show me a business with a strong compliance culture, and I’ll show you a business with a strong sense of purpose, service, and valued teamwork.

Glenn S. Phillips, the president of Forte' Incorporated, works with business leaders who want to leverage technology and understand the often hidden risks within. He is the author of the book Nerd-to-English and you can find him on twitter at @NerdToEnglish.

Glenn works with business leaders who want to leverage technology and understand the often hidden risks awaiting them. The Founder and Sr. Consultant of Forte' Incorporated, Glenn and his team work with business leaders to support growth, increase profits, and address ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-6093
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-6196
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSp...

CVE-2014-7247
Published: 2014-11-25
Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro Pro 2; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen; and Ichitaro 2014 Tetsu allows remote attackers to execute arbitrary code via a crafted file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?