Chapter 44. What Is Good Cyber Hygiene Within Information Security?
Lauren Zink
Everyone has a daily routine that they follow that is unique to them and typically includes maintaining personal hygiene throughout some aspect of their day. Security hygiene must be just as important as the personal hygiene that everyone already practices (or should) day in and day out. One of the biggest threats to a company can be their people, and not necessarily in a malicious way, but typically just by being negligent or not knowing better due to never being taught good security habits in the first place. This is why decent cyber hygiene is imperative at all levels of the organization and should be a main priority of the security team.
Solid hygiene in information security needs to be incorporated into all aspects of the security program from people to processes and even technology. No shortcuts should be taken, and it must never be assumed that tools and technology alone can protect an organization. A multilayered approach that incorporates governance and compliance as well as security training and awareness into everyday security operations in all of its facets is truly the best approach when it comes to securing an organization, its people, and its assets.
Oftentimes, there may be employees such as those on the technology teams or even the executives that may think they should be exempt from ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access