by Hal Flynn
OPERATIONS MANUAL Information Protection Center
Stage 0 - Passive
This particular IPC began with a relative "green field" for security. It had the creation of policies, guidelines and awareness initiative as its initial responsibilities. Most organisations will have some security group already in place handling policy and awareness programs.
Organisational and Departmental Policies: The IPC's activities in environmental scanning and VA give it a unique and integrated view of the organisation's security posture. The IPC will assist in policy formulation at both the departmental and organisation wide level.
Awareness and Education: The center, in addition to the more technical side, will initiate awareness programs as well as system and network security training for system administrators and network managers. The following represent different mechanisms that will be used to educate and improve awareness:
An important mission of the IPC is education and awareness of its constituency on issues relating to security. Studies have shown that there is a direct correlation between the level of system knowledge of system administrators and the level of security in an information system. System education and training has the most impact in all area of system management. As stated earlier one of the IPC prime objectives to is support the system owners and administrator in their efforts to understand and implement security measures. The IPC will be proactive in all areas of network security education and public awareness by helping system administrators, providing advice, making presentations, writing articles and by being available with expertise and assistance. The IPC provides an infrastructure service.
The following represent different mechanisms that will be used to educate and improve awareness.
Original development of these pages was supported by the Province of Manitoba
The content is maintained by Andrew Mackie
Last modified: April 29, 2000
This article originally appeared on SecurityFocus.com -- reproduction in whole or in part is not allowed without expressed written consent.