330 likes | 1.09k Views
Security Awareness, Training, and Education. JSAC April 2013 Jim Bass. JSAC. “ A Security Awareness Program Sets the Stage for Training by Changing Organizational Attitudes to Realize the Importance of Security and Adverse Consequences of Failure.”.
E N D
Security Awareness, Training, and Education JSAC April 2013 Jim Bass JSAC
“A Security Awareness Program Sets the Stage for Training by Changing Organizational Attitudes to Realize the Importance of Security and Adverse Consequences of Failure.” National Institute of Standards and Technology
…..Say That Again……..? • Awareness • The Threat Is Real • Dire Consequences May Ensue • Training • Compliance with NISPOM, Program Regulations, ITAR, etc. • Gaining Skills • Education • Ongoing process of enhancing knowledge, remembering facts and understanding concepts
NISPOM 3-100 “Contractors shall provide all cleared employees with security training and briefings commensurate with their involvement with classified information.”
Initial Briefing – Keep It Simple Threat Awareness Overview of the Classification System Reporting Requirements Procedures and Duties Associated with the Job Who to Call!!!!!!!!
Threat Awareness What is the Threat International, Domestic, Industrial Espionage, Foreign Intelligence, What Methods are Employed to Collect Elicitation, PHISHING, Foreign Contacts, Social Media, IT Intrusions Recent Cases Just GOOGLE “Recent Espionage Cases” DSS, FBI, NCIS, AFOSI, 902nd MI Group Current Collection Trends
Overview of the Classification System No Need to Drill Too Deep Three Levels of Classification and What They Mean Safeguarding AIS CAVEATS NATO, CNWDI, RD, etc. Marking Requirements Documents, Media, Hardware, etc.
Reporting Requirements Very Important !!! Suspicious Contacts Security Violations Adverse Information Foreign Travel (if required) Foreign Contact Attendance at Trade Shows or Other Events with Significant Foreign Presence
Security Procedures and Duties Applicable to the Job Lots of Foreign Travel or Contact? Working in a Closed Area? AIS ? Marketing or Business Development? Special Briefings Required ? R&D ? Manufacturing ?
Know Your Audienceor Training the Reluctant Marketeer Executive Level Briefings….short and to the point. Tell them What they NEED to Know. International Marketing and Business Development. Awareness and Reporting Requirements Dangers of Complacency ITAR and EAR - Especially in Light of Export Reform CI Subject Matter Expert Briefings and Debriefings Collect Business Cards
Subject Matter Experts Can Enhance and Lend Extra Credibility DSS OSI NCIS 902nd MI Group Legal Department Export Compliance/Empowered Officials
Awareness, Education, and Training as a Product Changing Organizational Attitudes
Resources and Methods Company Newsletters Great for Special Events or Current Topics “Security Slot” Desktop Publishing Website Space on the Company Website or Build a Security Website Security Bulletins Videos Expensive to Produce Commercially Available Computer Based Products
Other Stuff…….. Posters Some Commercially Available Best if Geared to Your Company Desktop Reminders Great for End of Day Checks Giveaways Pens, Rulers, Lanyards, etc. Pamphlets
Visual Advertising Readable A Quick, Easily Understood Message Legible “Don’t Make Me Work” Well Organized Not Busy, Not Cluttered Succinct
¡Los campesinos no esasí... la tierraesmía. Ahorabaje! General Francisco Franco.
Don’t Neglect Your Own Training • NCMS • JSAC • ASIS • National Security Institute – IMPACT • DSS • Network, Network, Network Some More
“The single greatest obstacle to espionage is education.” StanislavLevchenko, former KGB officer.
Key to Effectivity Reinforce Reinforce Reinforce
Jim Bass james.a.bass@lmco.com 972-603-2250 682-554-6657