Applying Adult Education Principles to Security Awareness Programs

Chris Hare · Auerbach Publications eBooks · 2011

As enterprise risks and threats change almost daily, it is critical for the enterprise to achieve a reliable security program. An investment in security outsourcing needs to be considered in the context of managing business risk. As we know, risks can be accepted, mitigated, avoided, or transferred. Outsourcing occurs when an enterprise secures/purchases products and/or services from a third party, as opposed to producing them in-house. Security outsourcing, whether it is long or short term, has pros and cons; depending on how and what the enterprise has security outsourced, it can turn out to be good or bad. One thing to remember with security outsourcing is that cost is only a short-term leverage for security outsourcing, because everyone moves toward limiting costs. Some of the benefits that will be discussed are that security outsourcing can focus attention on critical issues, more-predictable costs, and, potentially, greater flexibility and adaptability for your security services. Selecting a security outsourcer can combine advanced technology with expert human analysis, enabling an enterprise to cost-effectively strengthen its security posture, and provide a level of technology and expertise that ensures rapid response to real threats. While a cost decision may make it easy to select a security outsourcer, any notion that security is a matter of simply protecting the network perimeter is hopelessly out of date. Enterprises now recognize the importance of “defense in depth,” which involves a comprehensive approach to securing critical assets, networks, and information systems while implementing robust defenses against hackers, viruses, and other online threats.

Read the paper · More papers on PaperTik