Developing a Full- Spectrum Security Training Program



Similar documents
A LARGE- SCALE IMPLEMENTATION OF SYNCHRONOUS TECHNOLOGY FOR TEACHING AND LEARNING IN THE SCHOOL OF SCIENCE AND TECHNOLOGY

CFITS Industry Partners

FUNNELBRAIN ONLINE MARKETING GET EDUCATED ON THE SITE THE DELIVERS QUALIFIED STUDENTS TO YOUR SCHOOL. FunnelBrain

Interna'onal Standards Ac'vi'es on Cloud Security EVA KUIPER, CISA CISSP HP ENTERPRISE SECURITY SERVICES

Ge#ng Started with the Unidesk Solu5on Partner Program. Copyright Unidesk Corpora3on

Change Management Strategies to Increase Adop5on of Systems, Programs and Processes

Exchange of experience from a SuccessFactors LMS Implementa9on

HOW TO CREATE APPS FOR TRAINING. A step- by- step guide to crea2ng a great training app for your company

Disaster Recovery Planning and Implementa6on. Chris Russel Director, IT Infrastructure and ISO Compu6ng and Network Services York University

Phone Systems Buyer s Guide

San Jacinto College Banner & Enterprise Applica5on Review Task Force Report. November 01, 2011 FINAL

Challenges of PM in Albania and a New. Professional Perspec8ve. Prepared by: Dritan Mezini, MBA, MPM B.S. CS

CS 5150 So(ware Engineering Evalua4on and User Tes4ng

UAB Cyber Security Ini1a1ve

A wiki is nothing more than a website that is op-mized for easy edi-ng,

IT Change Management Process Training

The Pros and Cons of Organiza2on

Special Report. RESULTS BASED Onboarding Evalua/on Tools and Metrics. Sign up to get your free report today!

Program Model: Muskingum University offers a unique graduate program integra6ng BUSINESS and TECHNOLOGY to develop the 21 st century professional.

Online Enrollment Op>ons - Sales Training Benefi+ocus.com, Inc. All rights reserved. Confiden>al and Proprietary 1

High School Juniors Views on Free Enterprise and Entrepreneurship: A Na<onal Survey

How to write an effec-ve DIGITAL MARKETING STRATEGY. Secrets from the professionals

Application of Supply Chain Concepts to the Analysis Process

Master of Science in Physics

Part 1 : STRATEGIC : But let s begin with WHY : Why are we doing this?

Cloud Infrastructure Services Survey: Key UK Takeaways. Survey conducted by

Effec%ve AX 2012 Upgrade Project Planning and Microso< Sure Step. Arbela Technologies

The Real Score of Cloud

Poten&al Impact of FDA Regula&on of EMRs. October 27, 2010

Social Media Marke-ng for Academic Research

MAXIMIZING THE SUCCESS OF YOUR E-PROCUREMENT TECHNOLOGY INVESTMENT. How to Drive Adop.on, Efficiency, and ROI for the Long Term

- Welcome to AdvisorLoans

Developing Your Roadmap The Association of Independent Colleges and Universities of Massachusetts. October 3, 2013

Syndromic Surveillance BioSense Onboarding in Arizona

Fixed Scope Offering (FSO) for Oracle SRM

Provider Communica/on Interven/on at a Federally Qualified Health Center- based Farmers' Market: Implica/ons for Implementa/on Science

Merit Member Conference 2015 Does Migra+ng to a Virtualized Data Center Make Sense in Higher Educa+on?

Capitalize on your carbon management solu4on investment

FTC Data Security Standard

Delivering Wow! JOIN US! ENGAGE2014: The Art & Science of Employee Communications June 2 guidespark.com/engage2014 Silicon Valley

Range of Organiza7onal Approaches

Guidelines and Recommenda/ons on e- learning in VET

Introducing the Champlain College trued Alliance: An Overview for Federal Employees

Privileged Administra0on Best Prac0ces :: September 1, 2015

PROJECT PORTFOLIO SUITE

Case Study. The SACM Journey at the Ontario Government

Trends in Student Perspectives of their College Search #IACAC Conference

The Shi'ing Role of School Psychologists within a Mul7-7ered System of Support Framework. FASP Annual Conference October 29, 2015

Put the Magic in Your Marke4ng

Moving From Security to Governance, Risk, and Compliance? Campus Perspectives Panel

The Future of the Integrated Library System? Walter Nelson RAND Corpora1on walternelson.com

Powerful Change Management Communica4on A Benefits Case Study

Mul: channel communica:on increases your chances of reaching and mo:va:ng more of your audience.

This presenta,on covers the essen,al informa,on about IT services and facili,es which all new students will need to get started.

Interac(ve Broker (UK) Limited Webinar: Proprietary Trading Groups

Pu?ng B2B Research to the Legal Test

Public Hearing for Consolida4ng the Small Schools Model for Improved Quality and Efficiency South Atlanta Educa4onal Complex

We are pleased to offer the following program to Woodstock Area Educators:

About the Board. Minnesota Board of Behavioral Health and Therapy 10/24/12. Minnesota Board of Behavioral Health and Therapy

Connec(ng to the NC Educa(on Cloud

Graduate Systems Engineering Programs: Report on Outcomes and Objec:ves

Legacy Archiving How many lights do you leave on? September 14 th, 2015

Alterna)ve Educa)onal Resources for Ontario. Telephone:

Digital Communication Agency

Top Practices in Health IT Compliance. Data Breach & Leading Program Prac3ces

Cloud Risks and Opportunities

DEFINING COMPONENTS OF NATIONAL REDD+ FINANCIAL PLANNING

Guide to iconnect. Enabling interac(on and collabora(on in real (me!

Building your cloud porbolio APS Connect

Honeycomb Crea/ve Works is financed by the European Union s European Regional Development Fund through the INTERREG IVA Cross- border Programme

Procurement and Supply Chain Management Online Training

Distance.fsu.edu. Dr. Susann Rudasill, Director Office of Distance Learning

2012 UC CUCSA Staff Engagement Survey Recommenda9on Report Summary Career Development. January 13, 2014

Healthy Bengal Program - Plans and Goals for 2015

Washback of a High Stakes Language Test: The impact on teachers. BAAL TEA SIG Pi# Building Conference Centre, Cambridge May 8, 2015

ITS Strategic Plan Enabling an Unbounded University

CSER & emerge Consor.a EHR Working Group Collabora.on on Display and Storage of Gene.c Informa.on in Electronic Health Records

The Top 8 Ways to Increase Country Club Revenue and Customer Loyalty: Build a Superior Wine Program

BPO. Accerela*ng Revenue Enhancements Through Sales Support Services

Dewar COEHS Meeting Documentation Form

North Atlanta High School Scheduling Informa6on Class of 2019 Rising 9 th Grade

Agenda. What Data Science Can Learn from Training in Biomedical Informa8cs: The OHSU Experience

Preparing Faculty for Online Teaching. Sandra L. Robinson, Dean

Bill Sieglein, Founder CSO Breakfast Club PLATINUM SPONSOR: SOLUTIONARY

Results. Delivered! Implement your Big Data plan

Business Analysis Center of Excellence The Cornerstone of Business Transformation

VoIP Security How to prevent eavesdropping on VoIP conversa8ons. Dmitry Dessiatnikov

Channel Bytes. Accelera'ng Managed Services

Why Buy Eaton: Trusted Source to Manage Power

Everything You Need to Know about Cloud BI. Freek Kamst

DTCC Data Quality Survey Industry Report

ICD- 10: Learning for a Successful Transi:on Part 2. Objec.ves for the Webinars. ICD- 10 Webinar Topics

B2B Offerings. Helping businesses op2mize. Infolob s amazing b2b offerings helps your company achieve maximum produc2vity

Cost Effec/ve Approaches to Best Prac/ces in Data Analy/cs for Internal Audit

Using Ac+ve Directory and LDAP for directory management kept in sync

Pu#ng a Human Face on the Issues of Our Veteran Students

Cloud Compu)ng in Educa)on and Research

UMLN Retreat Boston Public Schools Transition to MA 2011 Frameworks (CCSSM)

NZ On Air Digital Strategy

Update on the Cloud Demonstration Project

Transcription:

Developing a Full- Spectrum Security Training Program Wayne State University Compu3ng & Informa3on Kevin Hayes, CISSP, CISM Informa)on Security Officer Geoff Nathan Faculty Liason

Agenda Background Our First Pilot Program Implementa)on Program Results Feedback from You

Why We Didn t Already Have IT Security Awareness Educa)on Taking the training required effort people either would not or could not perform. Nobody in authority wanted to take on both the technical and poli)cal challenges. We had an old Blackboard course, but it was annoying to access & never updated.

So what changed? Threats are growing, crea)ng a technology arms race that s difficult to keep up with. People have been asking for training and guidance more frequently. We wanted to ensure a cohesive program was developed not just deliver sta)c and stale content in a one size fits all approach.

SeGng the Table for Change We get about 10 calls a day from vendors promising us the perfect technical solu)on that will solve all our security woes, but funding and staff difficult to come by. Academic environment makes it a challenge to put restric)ve controls in place. But, with a new administra)on came a new opportunity.

First Steps Large push by Informa)on Security Office and Quality, Communica)ons & Compliance Dra\ed a Program Charter. Audience will be all managers, IT staff, and individuals with enterprise system (Banner in our case) access about 2500 people. Charter approval by IT Risk/Oversight Group. Started with a Pilot Implementa)on directed at internal IT staff only.

Beginning the Pilot We were new at this and s)ll evalua)ng various goals. Decided to purchase online videos. Evaluated SANS STH and TeachPrivacy. Forced own department to take TeachPrivacy. Trickled content (2-3 per month) over a few months. Content loaded in Accelerate HR CMS.

What happened in the Pilot? 250 people watched the videos. Solicited and measured feedback: These videos are a joke at best. The content is passable, but the quality of the so\ware and presenta)on is deplorable. I would not pay anyone for this service, but I might show it to my less technically literate employees if it were free and there were no beger free alterna)ves.

The Pilot showed deficiencies Half people liked trickle, half liked all at once. Content did not use WSU terminology or policies. Issues with clarity and wording of quiz ques)ons. Videos had poor produc)on: monotone narra)on, use of clip art, low audio quality.

Pilot conclusions Content was good, delivery not so much. People s)ll wanted to learn things, kinda. Resistance for taking the training: I already know this I don t have )me The system is frustra)ng to use There s no point to this We knew we had to make significant changes.

A light turns on Our primary job is to teach things. Why are we limi)ng ourselves? News Flash: People learn differently. Why can t we do different things to address the underlying reasons people won t take the training?

A star is born We decided to offer different training methods. Use same learning objec)ves for all training. Taking any one training method will cer)fy you. Learn to be flexible via three op)ons: Online Videos In- Person Seminar Advanced Placement Exam Created a new project plan for implementa)on.

A few more goals Did not want to exclude any employees. Wanted content to change frequently and be dynamic. Doesn t require substan)al resources to maintain. Gelng program started took several people many months to iden)fy and iron out many wrinkles.

Different training; same educa)on. No mager how you learn, content is the same: 1. Need for IT Security 2. Properly Securing Data 3. Creden)al Management 4. Phishing & Email Agacks 5. Dealing with Malware 6. Repor)ng IT Security Incidents Goal is to make people aware of security.

OpQon One: Updated Online Videos Online videos are great for self- starters who want to knock out bits and pieces here and there. Purchased selec)on of training videos from Inspired elearning Addressed produc)on quality. 3 modules for staff, 4 for managers. Installed in Accelerate HR LMS Blackboard had issues with >1000 registra)on and large gradebooks.

OpQon One: Updated Online Videos

OpQon Two: Created In- Person Seminar Created 90 minute presenta)on. Held across campus several )mes a month. Have AM and PM sessions on a Friday. Sessions held in different campus buildings. Allows for more interac)vity and tradi)onal learning. Sign up using exis)ng training registra)on system.

OpQon Two: Sign- up facility

OpQon Three: Created Test- Out Op)on For those that already know security (or at least claim to). Created online 24 Ques)on Advanced Placement Exam in Qualtrics based on learning objec)ves and program content. Only one try permiged per 12 months. No easy ques)ons. High Passing percentage required (85%).

OpQon Three: Created Test- Out Op)on

Keeping the training simple Have an answer for every yes, but Created portal landing page: hgps://compu)ng.wayne.edu/securityawareness Try for minimal- click solu)ons where possible. Created Program FAQ and Knowledge Base with )ps and acqonable advice on security topics. Made easy quick reference sheet.

Comes with a handy hand- out

Tracking Program Comple)on Our web developers created a web applica)on to consolidate comple)on data: Weekly CSV Import for Online Videos AUendance Sheet for In- Person Seminars Qualtrics HTTP POST Call for AP Test Permit managers to see progress of their employees and department as a whole. Awesome spread sheet developed during web applica)on development.

TesQng the new approach Perform beta tes)ng and solicit feedback for all three methods of training: Gave demo of seminar to C&IT staff. AP Test to select Provost staff. (AVP s and Deans Council) Online videos to HR staff. Very posi)ve feedback on all approaches. Feedback used to fine- tune each offering.

Making it rewarding Training should not be one- way effort. Give something tangible back to those who toiled. Cer)ficate on fancy paper and is JPEG- signed by CIO, ISO, & Faculty Liaison. Congratula)ons leger physically signed by ISO. People have been reques)ng and proudly displaying their cer)ficates.

Fancy cer)ficate paper: 10 cents each. Employees voluntarily showcasing their cer)ficates: PRICELESS.

Making the Push Provost s office criqcal to gelng off the ground especially a\er the Pilot phase. Provost kept in the loop during all beta tes)ng phases. Provost insisted their office, as well as all the deans and senior staff, be trained first. Email message from our president sent to the iden)fied popula)on of 2500 people.

Midflight Changes Execu)ve management needed shorter seminar. Really difficult to cut presenta)on by one- third. Less background informa)on and content review. Directly focus on key points. Break up regular seminar to include breaks. Wording changes in AP exam. Reduce AP exam passing grade from 90% to 85%

Final & Current Product Comprehensive, mul)- modal training op)ons. Not )me intensive; less than two hours. Simple to access. Support from execu)ve management. Leverage good reputa)on of IT and ISO. Not a lot of ongoing InfoSec )me investment: 4-6 hours per month for Seminars 30 Minutes per week for cer)ficates.

Analyzing Program Results Con)nue to measure and evaluate all training op)ons. All topics by far rated as Very Useful by agendees, scoring at least 6.5 out of 7. Giving personal anecdotes and stories the most effec)ve in gelng informa)on across.

Security Training teaches 12 How much do you feel you personally learned? 10 8 6 4 2 0 Nothing Few Things Fair Amount A Whole Lot

Security Training is valuable 95% of respondents rated the amount of content delivered as Just Right. All respondents felt this training met their expecta)ons, with 42% of them having their expecta)on exceeded. Respondents are ra)ng the training as valuable, applicable, and recommend it to their coworkers.

Security Training is accepted 16 Applicable Valuable Recommended 14 12 10 8 6 4 2 0 1 2 3 4 5 Worst Best

Security Training is working Spearheaded by Provost, all Deans & Senior Staff. Over 500 individuals have been cer)fied. All three training op)ons are proving successful. 134 12% 110 27% 221 61% AP Test Videos Seminar

Security Training is working Official Program Rollout March 1 st Steady Cer)fica)on Progress; about 50 per week a\er ini)al surge. Managers manda)ng training for their staff. 400 350 300 250 200 150 100 50 Cer)fica)ons over Time 0 12/10/2014 1/10/2015 2/10/2015 3/10/2015

Feedback on Security Training I thought the training program was well- conceived and informa3ve. It was appropriate for WSU employees at a wide range of posi3ons within the university. The speakers had solid exper3se and experience with the topic and made the presenta3ons interes3ng and engaging. Your examples of incidents were good and relevant to me.

Feedback on Security Training I thought it was an excellent training session; Geoff and Kevin are knowledgeable, ar3culate, and they made the session entertaining. The training was very informa3ve and I think that all staff should alend one of the sessions if possible. Thanks!

Feedback on Security Training from a faculty member (!) The commilee was one of the first to receive an excep3onal presenta3on on internet security. I have sat on the FSST commilee for about seven years and to the best of my recollec3on have never before seen a presenter receive a round of applause. I encourage you and your chairs to invite them to present at their departmental mee3ngs.

Security Training is ongoing Content con)nually updated based on par)cipant feedback and new threats. Updated informa)on in training materials New Knowledge Base ar)cles and ac)onable )ps Send courtesy emails to cer)fied employees every few months with applicable content. We come to users and hold dedicated seminars for staff around their schedule.

Future Goals Security Awareness cer)fica)on will be needed for enterprise system access. Wai)ng for Cri)cal Mass of cer)fica)ons. Mandated by University IT Governance Council. Iden)ty Management will be used to enforce. Cer)fica)on currently lasts two years, eventually move down to one. Make part of HR onboarding process.

Your Feedback & Discussion

Developing a Full- Spectrum Security Training Program Wayne State University Compu3ng & Informa3on Kevin Hayes, CISSP, CISM Informa)on Security Officer Geoff Nathan Faculty Liaison