Educause Security Discussion mailing list archives

Re: Security Awareness Training for Managers of Decentralized IT Systems


From: Kelley Bogart <bogartk () EMAIL ARIZONA EDU>
Date: Fri, 9 Jul 2010 13:34:21 -0700

Hi Daniel.

 

The University of Arizona has a powerpoint presentation for our dept.
Information Security Liaisons (ISL's) many of which are business managers
not technical.  This presentation is available on our ISL page
(http://security.arizona.edu/isl).  There are no notes on the ppt version,
so there is a record version available that provides the talking notes.

 

Additionally, we recently released an online version of our mandatory all
employee security awareness session that includes some of the same concepts.
The ppt and pdf version are available at
(http://security.arizona.edu/infosecessentials#electronic) and they include
the talking notes.  Much of this presentation includes points which I would
consider the pointers that managers need to hear in order to understand and
support information security efforts. 

 

And lastly are basics awareness page is full of ppt and recorded versions of
the awareness day/week sessions.  

 

 

Kelley J. Bogart, CISSP                         

wildcatSenior Information Security Specialist   
                 University of Arizona
                 Office of Information Security
                 Computer Center - Room 203
                 Tucson, Az 85721
                 Office    (520)626-8232

 

From: The EDUCAUSE Security Constituent Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Sarazen, Daniel
Sent: Friday, July 09, 2010 12:16 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Security Awareness Training for Managers of
Decentralized IT Systems

 

Hi All,

 

We have a large population of decentralized departmental IT systems and
typically these are under the direction of Business Management who have
little to no IT background. I'm considering providing the management of
decentralized IT systems within our system with an Information Security
Awareness presentation and was wondering if anybody had prepared anything
similar. 

 

I tried something similar in the past, using ISO 27002 controls, but they
just sent their IT Administrators and completely missed my point. 

 

Thanks

 

 

 


http://media.umassp.edu/pix/mail/umass.gif

:: Daniel Sarazen, CISSP, CISA

:: Senior Information Technology Auditor
:: University Internal Audit
:: University of Massachusetts President's Office


:: 774-455-7558

:: 781-724-3377 Cell
:: 774-455-7550 Fax
:: Dsarazen () umassp edu


University of Massachusetts : 333 South St. : Suite 450 : Shrewsbury, MA
01545 :  <http://www.massachusetts.edu/> www.massachusetts.edu

 

 


Current thread: