SlideShare a Scribd company logo
Information Security
   (un)awareness




          Marc Vael
     International Vice-President
ā€œMy management
just does not ā€œgetā€
    information
     security!ā€
      Anonymous CISO of a large financial institution
ā€œI am overwhelmed with
 all the passwords I have
 to remember. I just write
them down & leave them
     with my executive
         assistant.ā€
     Anonymous manager working in an insurance company
ā€œManagement has
authorized acquisition of
security monitoring tools,
but they did not give me
any budget for people to
  do this monitoring.ā€
     Anonymous CISO of a multinational service organisation
ā€œSure, I support
  information security,
 but my people need to
work and make money.ā€
             Anonymous CEO of a retailer
ā€œOur information security
department keeps getting
 more tools, but I do not
 think we are any more
         secure.ā€
        Anonymous CRO of a large financial institution
ā€œSecurity policy is one
thing. Reality is another.ā€
         Anonymous COO from a consulting company
ā€œAll that information
 security people do is
        say ā€œNo!ā€.
They should learn how
    we really work.
         Angry manager of a governmental agency
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Cyberwarfare is
"the fifth domain of
warfareā€œ
Impact of an attack on the business
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
People are the weakest link.
You can have the best technology,
firewalls, intrusion-detection systems,
biometric devices - and somebody
can call an unsuspecting employee.
That's all she wrote, baby.
They got everything.
                     Kevin Mitnick, ex hacker, IT security consultant.
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Business Model for Information Security
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Managing risks appropriately
Risk always exists!
 (whether or not it is
detected / recognised
by the organisation).
Information security awareness (sept 2012) bis handout
EDUCATION!
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
Corporate governance : ERM = COSO




   Support from Board of Directors &
       Executive Management
Policies & Standards
Project Management
Providing proper funding
Providing proper resources
Measuring performance
Review / Audit
Information security awareness (sept 2012) bis handout
Your security solution
   is as strong …




               … as its weakest link
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
www.isaca.org/knowledgecenter
Information security awareness (sept 2012) bis handout
www.isaca.org/cobit
For more information…
 Marc Vael
 International Vice-President
 Chairman of the Knowledge Board

 ISACA



 http://www.isaca.org/

         marc@vael.net
         http://www.linkedin.com/in/marcvael
         @marcvael

More Related Content

PDF
Security Awareness Training: Are We Getting Any Better at Organizational and ...
Enterprise Management Associates
Ā 
PDF
Customer information security awareness training
AbdalrhmanTHassan
Ā 
PPSX
Security Awareness Training
William Mann
Ā 
PPT
Information Security Awareness And Training Business Case For Web Based Solut...
Michael Kaishar, MSIA | CISSP
Ā 
PPTX
GRRCON 2013: Imparting security awareness to all levels of users
Joel Cardella
Ā 
PDF
Cybersecurity Employee Training
Paige Rasid
Ā 
PDF
End-User Security Awareness
Surya Bathulapalli
Ā 
PPT
End User Security Awareness Presentation
Cristian Mihai
Ā 
Security Awareness Training: Are We Getting Any Better at Organizational and ...
Enterprise Management Associates
Ā 
Customer information security awareness training
AbdalrhmanTHassan
Ā 
Security Awareness Training
William Mann
Ā 
Information Security Awareness And Training Business Case For Web Based Solut...
Michael Kaishar, MSIA | CISSP
Ā 
GRRCON 2013: Imparting security awareness to all levels of users
Joel Cardella
Ā 
Cybersecurity Employee Training
Paige Rasid
Ā 
End-User Security Awareness
Surya Bathulapalli
Ā 
End User Security Awareness Presentation
Cristian Mihai
Ā 

What's hot (17)

PPTX
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Stephen Cobb
Ā 
PPT
New Hire Information Security Awareness
hubbargf
Ā 
PPTX
Security Awareness Training - For Companies With Access to NYS "Sensitive" In...
David Menken
Ā 
PPTX
Awareness Training on Information Security
Ken Holmes
Ā 
PPT
Building An Information Security Awareness Program
Bill Gardner
Ā 
PDF
Raising information security awareness
Terranovatraining
Ā 
PPT
Executive Information Security Training
Angela Samuels
Ā 
PPTX
Basic Security Training for End Users
Community IT Innovators
Ā 
PPTX
The need for effective information security awareness practices.
CAS
Ā 
PDF
Cyber Security Awareness
Ramiro Cid
Ā 
PPTX
Employee Awareness in Cyber Security - Kloudlearn
KloudLearn
Ā 
PPTX
information security awareness course
Abdul Manaf Vellakodath
Ā 
PDF
Best Practices for Security Awareness and Training
Kimberly Hood
Ā 
PPTX
IT & Network Security Awareness
The Network Support Company
Ā 
PDF
Infosec IQ - Anti-Phishing & Security Awareness Training
David Alderman
Ā 
PDF
Employee Security Awareness Program
davidcurriecia
Ā 
PPTX
Network Security for Employees
OPSWAT
Ā 
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Stephen Cobb
Ā 
New Hire Information Security Awareness
hubbargf
Ā 
Security Awareness Training - For Companies With Access to NYS "Sensitive" In...
David Menken
Ā 
Awareness Training on Information Security
Ken Holmes
Ā 
Building An Information Security Awareness Program
Bill Gardner
Ā 
Raising information security awareness
Terranovatraining
Ā 
Executive Information Security Training
Angela Samuels
Ā 
Basic Security Training for End Users
Community IT Innovators
Ā 
The need for effective information security awareness practices.
CAS
Ā 
Cyber Security Awareness
Ramiro Cid
Ā 
Employee Awareness in Cyber Security - Kloudlearn
KloudLearn
Ā 
information security awareness course
Abdul Manaf Vellakodath
Ā 
Best Practices for Security Awareness and Training
Kimberly Hood
Ā 
IT & Network Security Awareness
The Network Support Company
Ā 
Infosec IQ - Anti-Phishing & Security Awareness Training
David Alderman
Ā 
Employee Security Awareness Program
davidcurriecia
Ā 
Network Security for Employees
OPSWAT
Ā 
Ad

Similar to Information security awareness (sept 2012) bis handout (20)

PDF
Information security (un)awareness by Marc Vael
CONFENIS 2012
Ā 
PPT
Information security background
Nicholas Davis
Ā 
PPT
Information Security Background
Nicholas Davis
Ā 
PPTX
Information Security vs IT - Key Roles & Responsibilities
Kroll
Ā 
PDF
beyond_the_firewall_0103
Jack McCullough
Ā 
PPTX
ISO27k Awareness presentation.pptx
harigopala
Ā 
PDF
How To Promote Security Awareness In Your Company
danielblander
Ā 
PPTX
People are the biggest risk
Evan Francen
Ā 
PDF
FDseminar IT Risk - Yuri Bobbert - Antwerp Management School
FDMagazine
Ā 
PDF
ISO 27001 Awareness IGN Mantra 2nd Day, 1st Session.
IGN MANTRA
Ā 
PPTX
ISM-CS5750-01.pptx
RashidSahito1
Ā 
PDF
Information Security Governance at Board and Executive Level
Koen Maris
Ā 
PDF
Describe two methods for communicating the material in an Informatio.pdf
archgeetsenterprises
Ā 
PPTX
Information security for business majors
Paul Melson
Ā 
PDF
Chapter 12 iso 27001 awareness
newbie2019
Ā 
PDF
My_notes_part1.pdf
PhilLopez4
Ā 
PPTX
FROM STRATEGY TO ACTION - Vasil Tsvimitidze
DataExchangeAgency
Ā 
PDF
Security, Audit and Compliance: course overview
Edinburgh Napier University
Ā 
PDF
Cissp notes
Jagbir Singh
Ā 
PPTX
ISO27k Awareness presentation v2.pptx
Napoleon NV
Ā 
Information security (un)awareness by Marc Vael
CONFENIS 2012
Ā 
Information security background
Nicholas Davis
Ā 
Information Security Background
Nicholas Davis
Ā 
Information Security vs IT - Key Roles & Responsibilities
Kroll
Ā 
beyond_the_firewall_0103
Jack McCullough
Ā 
ISO27k Awareness presentation.pptx
harigopala
Ā 
How To Promote Security Awareness In Your Company
danielblander
Ā 
People are the biggest risk
Evan Francen
Ā 
FDseminar IT Risk - Yuri Bobbert - Antwerp Management School
FDMagazine
Ā 
ISO 27001 Awareness IGN Mantra 2nd Day, 1st Session.
IGN MANTRA
Ā 
ISM-CS5750-01.pptx
RashidSahito1
Ā 
Information Security Governance at Board and Executive Level
Koen Maris
Ā 
Describe two methods for communicating the material in an Informatio.pdf
archgeetsenterprises
Ā 
Information security for business majors
Paul Melson
Ā 
Chapter 12 iso 27001 awareness
newbie2019
Ā 
My_notes_part1.pdf
PhilLopez4
Ā 
FROM STRATEGY TO ACTION - Vasil Tsvimitidze
DataExchangeAgency
Ā 
Security, Audit and Compliance: course overview
Edinburgh Napier University
Ā 
Cissp notes
Jagbir Singh
Ā 
ISO27k Awareness presentation v2.pptx
Napoleon NV
Ā 
Ad

More from Marc Vael (20)

PDF
How secure are chat and webconf tools
Marc Vael
Ā 
PDF
my experience as ciso
Marc Vael
Ā 
PDF
Advantages of privacy by design in IoE
Marc Vael
Ā 
PDF
Cybersecurity governance existing frameworks (nov 2015)
Marc Vael
Ā 
PDF
Cybersecurity nexus vision
Marc Vael
Ā 
PDF
ISACA Reporting relevant IT risks to stakeholders
Marc Vael
Ā 
PDF
Cloud security lessons learned and audit
Marc Vael
Ā 
PDF
Value-added it auditing
Marc Vael
Ā 
PDF
ISACA Internet of Things open forum presentation
Marc Vael
Ā 
PDF
hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?
Marc Vael
Ā 
PDF
The value of big data analytics
Marc Vael
Ā 
PDF
Social media risks and controls
Marc Vael
Ā 
PDF
The view of auditor on cybercrime
Marc Vael
Ā 
PDF
ISACA Mobile Payments Forum presentation
Marc Vael
Ā 
PDF
Belgian Data Protection Commission's new audit programme
Marc Vael
Ā 
PDF
ISACA Cloud Computing Risks
Marc Vael
Ā 
PPTX
ISACA smart security for smart devices
Marc Vael
Ā 
PPTX
Securing big data (july 2012)
Marc Vael
Ā 
PDF
Valuendo cyberwar and security (jan 2012) handout
Marc Vael
Ā 
PDF
How to handle multilayered IT security today
Marc Vael
Ā 
How secure are chat and webconf tools
Marc Vael
Ā 
my experience as ciso
Marc Vael
Ā 
Advantages of privacy by design in IoE
Marc Vael
Ā 
Cybersecurity governance existing frameworks (nov 2015)
Marc Vael
Ā 
Cybersecurity nexus vision
Marc Vael
Ā 
ISACA Reporting relevant IT risks to stakeholders
Marc Vael
Ā 
Cloud security lessons learned and audit
Marc Vael
Ā 
Value-added it auditing
Marc Vael
Ā 
ISACA Internet of Things open forum presentation
Marc Vael
Ā 
hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?
Marc Vael
Ā 
The value of big data analytics
Marc Vael
Ā 
Social media risks and controls
Marc Vael
Ā 
The view of auditor on cybercrime
Marc Vael
Ā 
ISACA Mobile Payments Forum presentation
Marc Vael
Ā 
Belgian Data Protection Commission's new audit programme
Marc Vael
Ā 
ISACA Cloud Computing Risks
Marc Vael
Ā 
ISACA smart security for smart devices
Marc Vael
Ā 
Securing big data (july 2012)
Marc Vael
Ā 
Valuendo cyberwar and security (jan 2012) handout
Marc Vael
Ā 
How to handle multilayered IT security today
Marc Vael
Ā 

Recently uploaded (20)

PDF
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
Ā 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
Ā 
PDF
Chapter 1 Introduction to CV and IP Lecture Note.pdf
Getnet Tigabie Askale -(GM)
Ā 
PPT
L2 Rules of Netiquette in Empowerment technology
Archibal2
Ā 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
Ā 
PPTX
ChatGPT's Deck on The Enduring Legacy of Fax Machines
Greg Swan
Ā 
PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
Ā 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
Ā 
PDF
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
Ā 
PDF
DevOps & Developer Experience Summer BBQ
AUGNYC
Ā 
PDF
REPORT: Heating appliances market in Poland 2024
SPIUG
Ā 
PDF
Cloud-Migration-Best-Practices-A-Practical-Guide-to-AWS-Azure-and-Google-Clou...
Artjoker Software Development Company
Ā 
PDF
Why Your AI & Cybersecurity Hiring Still Misses the Mark in 2025
Virtual Employee Pvt. Ltd.
Ā 
PDF
Software Development Methodologies in 2025
KodekX
Ā 
PDF
A Day in the Life of Location Data - Turning Where into How.pdf
Precisely
Ā 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
Ā 
PDF
Presentation about Hardware and Software in Computer
snehamodhawadiya
Ā 
PDF
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
Ā 
PPTX
Coupa-Overview _Assumptions presentation
annapureddyn
Ā 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
Ā 
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
Ā 
cloud computing vai.pptx for the project
vaibhavdobariyal79
Ā 
Chapter 1 Introduction to CV and IP Lecture Note.pdf
Getnet Tigabie Askale -(GM)
Ā 
L2 Rules of Netiquette in Empowerment technology
Archibal2
Ā 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
Ā 
ChatGPT's Deck on The Enduring Legacy of Fax Machines
Greg Swan
Ā 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
Ā 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
Ā 
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
Ā 
DevOps & Developer Experience Summer BBQ
AUGNYC
Ā 
REPORT: Heating appliances market in Poland 2024
SPIUG
Ā 
Cloud-Migration-Best-Practices-A-Practical-Guide-to-AWS-Azure-and-Google-Clou...
Artjoker Software Development Company
Ā 
Why Your AI & Cybersecurity Hiring Still Misses the Mark in 2025
Virtual Employee Pvt. Ltd.
Ā 
Software Development Methodologies in 2025
KodekX
Ā 
A Day in the Life of Location Data - Turning Where into How.pdf
Precisely
Ā 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
Ā 
Presentation about Hardware and Software in Computer
snehamodhawadiya
Ā 
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
Ā 
Coupa-Overview _Assumptions presentation
annapureddyn
Ā 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
Ā 

Information security awareness (sept 2012) bis handout