Читать книгу You CAN Stop Stupid - Ira Winkler - Страница 2
Table of Contents
Оглавление1 Cover
3 Introduction What Is Stupid? Do You Create Stupidity? How Smart Organizations Become Smart Not All Industries Are as Smart Deserve More Reader Support for This Book
4 I: Stopping Stupid Is Your Job 1 Failure: The Most Common Option History Is Not on the Users’ Side Today's Common Approach We Propose a Strategy, Not Tactics 2 Users Are Part of the System Understanding Users' Role in the System Users Aren't Perfect “Users” Refers to Anyone in Any Function Malice Is an Option What You Should Expect from Users 3 What Is User-Initiated Loss? Processes Culture Physical Losses Crime User Error Inadequate Training Technology Implementation UIL Is Pervasive
5 II: Foundational Concepts 4 Risk Management Death by 1,000 Cuts The Risk Equation Risk Optimization Risk and User-Initiated Loss 5 The Problems with Awareness Efforts Awareness Programs Can Be Extremely Valuable Check-the-Box Mentality Training vs. Awareness The Compliance Budget Shoulds vs. Musts When It's Okay to Blame the User Awareness Programs Do Not Always Translate into Practice Structural Failings of Awareness Programs Further Considerations 6 Protection, Detection, and Reaction Conceptual Overview Protection Detection Reaction Putting It All Together 7 Lessons from Safety Science The Limitations of Old-School Safety Science Most UIL Prevention Programs Are Old-School The New School of Safety Science Putting Safety Science to Use Safety Culture The Need to Not Remove All Errors When to Blame Users We Need to Learn from Safety Science 8 Applied Behavioral Science The ABCs of Behavioral Science Engineering Behavior vs. Influencing Behavior 9 Security Culture and Behavior ABCs of Culture Types of Cultures Subcultures What Is Your Culture? Improving Culture Behavioral Change Strategies Is Culture Your Ally? 10 User Metrics The Importance of Metrics The Hidden Cost of Awareness Types of Awareness Metrics Day 0 Metrics Deserve More 11 The Kill Chain Kill Chain Principles Deconstructing the Cyber Kill Chain Other Models and Frameworks Applying Kill Chains to UIL 12 Total Quality Management Revisited TQM: In Search of Excellence Other Frameworks COVID-19 Remote Workforce Process Activated Applying Quality Principles
6 III: Countermeasures 13 Governance Defining the Scope of Governance for Our Purposes Traditional Governance Security and the Business Analyzing Processes Grandma's House 14 Technical Countermeasures Personnel Countermeasures Physical Countermeasures Operational Countermeasures Cybersecurity Countermeasures Nothing Is Perfect Putting It All Together 15 Creating Effective Awareness Programs What Is Effective Awareness? Governance as the Focus Where Awareness Strategically Fits in the Organization The Goal of Awareness Programs Changing Culture Defining Subcultures Interdepartmental Cooperation The Core of All Awareness Efforts Metrics Gamification Getting Management's Support Enforcement Experiment
7 IV: Applying Boom 16 Start with Boom What Are the Actions That Initiate UIL? Metrics Governance Awareness Feeding the Cycle Stopping Boom 17 Right of Boom Repeat as Necessary What Does Loss Initiation Look Like? What Are the Potential Losses? Preventing the Loss Detecting the Loss Mitigating the Loss Determining Where to Mitigate Avoiding Analysis Paralysis Your Last Line of Defense 18 Preventing Boom Why Are We Here? Reverse Engineering Step-by-Step 19 Determining the Most Effective Countermeasures Early Prevention vs. Response Start with Governance Prioritize Potential Loss Define Governance Thoroughly Matrix Technical Countermeasures Define Awareness It's Just a Start 20 Implementation Considerations You've Got Issues Business Case for a Human Security Officer It Won't Be Easy 21 If You Have Stupid Users, You Have a Stupid System A User Should Never Surprise You Perform Some More Research Start Somewhere Take Day Zero Metrics UIL Mitigation Is a Living Process Grow from Success The Users Are Your Canary in the Mine
8 Index