Published: 18 April 2024
Summary
Cybersecurity leaders struggle to effectively drive secure behavior. This research helps leaders master the cybersecurity policy life cycle by developing a consistent cybersecurity policy framework and applying human-centric design to improve security policy development, delivery and diagnosis.
Included in Full Research
Overview
Key Findings
Cybersecurity policies are often ineffective because they are not actionable, comprehensible or pragmatic, nor are they easy to find for most employees.
Employees don’t understand the rationale for most cybersecurity policies, which results in apathy, but effective security leaders are dynamically supporting human-centric policy design in both the creation and the deployment of policy.
Cybersecurity leaders can no longer get away with stagnant document management that, although well-intentioned, often leaves the reader relegated to a passive role in policy enforcement.
Clients can log in to view the entire
document.