Abstract...

Managing the Human Factor in Information Security

David Lacey, ISSA-UK

Most security professionals now agree that information security is more of a people problem than a technical one. Yet few organisations do anything about it. But people are both the source of security breaches and the means of preventing them. And their influence is increasing with the growth in social networks. Traditional approaches to policy and education, however, are ineffective. People are too busy to read policies. And young recruits pay little attention to authority. We need to learn from fields that are more advanced in understanding how to transform human perception and behaviour.

Drawing on his book "Managing the Human Factor in Information Security", David Lacey will explain the nature of people and networks, and how to transform organisation culture using learning points from psychology, criminology and advertising, as well as three decades of practical experience in information security management. 

David Lacey's biography