19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Personnel Remarks<br />

____________________________________________________________________ .........................................<br />

S 3.8 Avoidance of factors impairing the<br />

organisational climate<br />

Initiation responsibility: Agency/company management; Head of<br />

Personnel Section; personnel<br />

committee/works council<br />

Implementation responsibility: Superiors; Personnel Section; personnel<br />

committee/works council<br />

A positive organisational climate motivates staff to observe <strong>IT</strong> security<br />

safeguards, while at the same time reducing the incidence of negligent or<br />

deliberate acts which can cause disruption to the <strong>IT</strong> operation. Efforts should<br />

therefore be made, also from an <strong>IT</strong> security point of view, to achieve a<br />

positive working atmosphere. <strong>The</strong>re are so many ways available for achieving<br />

this that only a selection of measures is given here, the appropriateness of<br />

which must be determined on a case-by-case basis:<br />

- provision of a social centre,<br />

- avoidance of overtime,<br />

- observance of rest breaks,<br />

- regulated division of responsibilities,<br />

- even distribution of workload,<br />

- performance-related pay.<br />

Communications problems in an organisation almost inevitably lead to<br />

security problems as well. In extreme cases, this can result in deliberate<br />

security violations. But even if the users merely find the security measures<br />

"annoying" because they have not been informed of the purpose of the<br />

measures, this can result in their being circumvented.<br />

Being the one to report bad news must not mean that the messenger has to live<br />

in fear of punishment. <strong>The</strong> organisational climate should be such that every<br />

person concerned is able to report security incidents within his/her own<br />

organisation and to tackle them openly as well.<br />

Financial incentives are not the only way to motivate staff, but it is especially<br />

important that they should feel their work is valued. Wherever possible, staff<br />

should be included in decisions. At the very least, they should be informed of<br />

the reasons for the decisions which have been made so that they become<br />

actively involved in implementing them.<br />

For example, often protests against the choice of certain hardware or software<br />

are couched in arguments on the part of the users that the hardware or<br />

software they have been allocated is not a secure as the one they preferred.<br />

Additional controls:<br />

- How is the organisational climate rated by the staff?<br />

- How do line managers rate the existing organisational climate?<br />

- Which factors having a negative influence on the organisational climate are<br />

most frequently mentioned?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Resolve any<br />

communication<br />

problems<br />

Staff motivation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!