Improving Security from the Ground Up
John O.D. Wylder · Information Systems Security · 2003
The goal of information security professionals through the years has been to not just get policies written but to also get compliance. They have long sought additional support in enforcing the information security policies of their companies. The support they have received usually comes from internal or external audit and has had limited success in influencing the behavior of the individuals who make up the bulk of the user community. Internal and external auditors have their own agendas and do not usually consider themselves prime candidates for the enforcement role. The security professional has had to look around the organization, trying to find the right person to help with the enforcement issue. This problem has become even more complex with the growth of Web-based applications and the resulting large increase in the size of the user community.