Perimeter

7/9/2012
11:54 AM
50%
50%

Being Compliant Is Not Only Training And Rules, It's Culture

Too many organizations teach compliance instead of live it

In high school, we all took the basics: language, math, and science. Now that a few years have passed (OK, more than a few for some of us), who could pass the final exams in those classes right now? Probably very few. Education fades from our memory unless regularly reinforced. But education and training alone are not enough. The habits we develop determine and drive what we are good at.

Just like individuals, organizations have habits as well -- cultural habits. Ever go to a restaurant with several horrible waiters? Odds are there were no great waiters in the place; the standard of service is simply not very high. It is likely that great waiters who happen to get hired will eventually either leave or become lazy waiters themselves.

If your colleagues are slack about security and compliance, then you are more likely to be slack about it as well. You may even be encouraged to be slack: “Hey, don’t spend time documenting that security process right now. We all know our data is safe, and I need your help on this other deadline.”

Maybe the data is safe that particular day. But what about the future, when months and months of skipped documentation leads to lost knowledge? Time passes, systems change, and staff leaves. Without regular reinforcement, the “things we all know” become a collection of “things we used to know.” Infrequent training alone can never fill this gap. Even frequent training, if not reinforced by your company culture, will be pointless.

As social creatures, most of us want to “just get along.” We can be conflict-averse and prefer to keep a low profile instead of speaking up for important processes if they are contrary to the work culture. After all, who wants to be a tattletale in a noncompliant culture?

I find restaurants with great wait staffs clearly spend a lot of time, and therefore money and time, training their staffs. But they also make a point to only keep staff that fits the culture of excellence. (If you damage our service reputation, then you can’t stay.) As time passes, the culture of service is ingrained and normal, not just an overhyped lesson from sporadic class instruction.

Likewise, I see great business organizations operating the same way. Training and rules are not the be-all, end-all for security and compliance. Rather, training and rules are used to provide the framework and support for excellence. Skimping on security and compliance efforts does more than break rules; it breaks cultural norms.

Show me a business with a strong compliance culture, and I’ll show you a business with a strong sense of purpose, service, and valued teamwork.

Glenn S. Phillips, the president of Forte' Incorporated, works with business leaders who want to leverage technology and understand the often hidden risks within. He is the author of the book Nerd-to-English and you can find him on twitter at @NerdToEnglish.

Glenn works with business leaders who want to leverage technology and understand the often hidden risks awaiting them. The Founder and Sr. Consultant of Forte' Incorporated, Glenn and his team work with business leaders to support growth, increase profits, and address ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
12 Free, Ready-to-Use Security Tools
Steve Zurier, Freelance Writer,  10/12/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
Most Malware Arrives Via Email
Dark Reading Staff 10/11/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
CVE-2018-18375
PUBLISHED: 2018-10-16
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.
CVE-2018-18376
PUBLISHED: 2018-10-16
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.
CVE-2018-18377
PUBLISHED: 2018-10-16
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.
CVE-2018-17534
PUBLISHED: 2018-10-15
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.