Eine sichere und verlässliche Informationssicherheitskultur ist in der heutige Lage für Banken so wichtig wie nie zuvor. Gewinnen Sie anhand unserer Success Story aus dem Bankensektor Einblick in unsere spannende Arbeit und erfahren Sie, wie Banken mit unserer Hilfe Ihre Mitarbeiter und Teams erfolgreich schulen konnten.
International Swiss Private Bank – Information Security Culture Assessment & Awareness Program
Information Security
(IS) is an important issue for a private bank. A number of steps such as staff information and clear desk flyers have been and are being taken to address and improve the quality of information security. However, to ensure that the required level of security is maintained, staff trainings are a vital part of this process.
The management has requested suggestions on steps that can be taken to implement a security awareness program and seeks assistance in a company wide rollout of this program.
Firstly, the IS-culture was assessed by means of a quantitative staff survey. Different subcultures have been identified which is a result of a merger into a single entity.
Secondly, countermeasures were defined in order to raise the maturity level of IS awareness. These measures were realized within a global awareness program.
The global IS awareness program included
- CEO film demonstrating the commitment of the management to the IS program
- Definition of six golden security rules
- An e-learning program including a test
- Management workshops
- IS awareness promotional material like posters and flyers for all staff and locations
- New IS awareness intranet presence
For the successful realization of this IS awareness program two factors were essential: On one hand that key people from Marketing & Communications as well as from Human Resources were part of the project team. On the other hand, the full commitment from executive board members was also crucial for the success of this IS awareness program. Indeed theses two factors were fundamental but in addition also important was an unique IS awareness brand. A unique branding was created for all communication measures such as the e-learning program, posters, flyers, management workshops and the intranet portal. The branding was represented by a photo which was created by the active cooperation of employees. It was a true eye catcher, while it perfectly represented the program it also raised the consciousness for the project. Hence, the program was very well perceived by the staff.
In a next step it is planned to evaluate the outcome of the IS awareness program through another quantitative assessment approach. Furthermore an IS awareness management process is going to be installed to constantly optimize the IS awareness level at the bank.
|