Story 1 - A failure that should never have happened.
4
Post Mortem
5
Culture the behaviors, beliefs, values, and symbols of a group that are passed along by communication and imitation from one generation to the next
6
Security the state of being free from danger or threat
7
Security Culture the behaviors, beliefs, values, and symbols of a group that help them be free from danger
8
Culture requires people Lets look at NOLACON NOLACON Culture
9
How can culture change? People Technology Policies
10
Policy Enforcement
11
Organizational Maturity
12
Story 2 - Persistence in the wake of oblivion
13
PreMortem What is the best case scenario?
14
Story Details Continued Talk to Pinky
15
More Story Details Again In the next meeting with Fred from Accounting
16
Story Conclusion Elevate to Angleton
17
Raising security awareness in developers
18
The need for training
19
Metrics Learning Metrics Measure the effectiveness of the learning activity · Surveys of before and after opinions and behaviours
20
Secure Coding Lunch'n Learn
21
Results On scale of 1 to 5 how knowledgeable are you of secure coding practices?
22
Results Continued On a scale of 1 to 5 how important is it to consider security while coding?
23
More Results I will be able to use the information in this class to improve the security of the code write.
24
Conclusions
25
Questions?
Description:
Explore strategies for evolving office security culture through selective breeding of ideas and practices in this conference talk from NolaCon 2016. Learn from real-world examples, including a critical failure and a persistent security initiative, to understand how culture change can be driven by people, technology, and policies. Discover methods for raising security awareness among developers, implementing effective training programs, and measuring the impact of learning activities. Gain insights into organizational maturity, policy enforcement, and the importance of secure coding practices. Examine survey results demonstrating the effectiveness of security awareness initiatives and leave with actionable strategies to improve your organization's security posture.
Evolving Your Office's Security Culture by Selective Breeding of Ideas and Practices