Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO identifies that despite having formal security policies, employees frequently bypass security controls when they perceive them as hindering productivity. This indicates a significant gap in the organization's security posture. Which of the following is the MOST effective long-term strategy to address this issue?

  1. AOutsource security awareness training to a third-party vendor to improve employee knowledge.
  2. BImplement stricter technical controls and monitoring to enforce policy compliance.
  3. CRedesign security processes and controls to be more user-friendly and integrate them into existing workflows, while fostering a positive security culture.
  4. DIncrease the frequency and severity of disciplinary actions for security policy violations.
Show answer & explanation

Correct answer: C. Redesign security processes and controls to be more user-friendly and integrate them into existing workflows, while fostering a positive security culture.

When employees bypass controls due to perceived productivity hindrance, simply adding more controls or punishment is often counterproductive. The most effective long-term strategy involves understanding user needs, making security user-friendly, integrating it into workflows, and fostering a positive security culture that values security as a business enabler.

Why the other options are wrong

  • A. While training is important, if controls are still cumbersome, training alone will not solve the underlying productivity versus security conflict.
  • B. Stricter controls without addressing the underlying usability issue can increase frustration and lead to new bypass methods.
  • D. Punishment without addressing root causes can create resentment and further disengagement, not long-term compliance.

Security Culture Integration

The process of embedding security principles and practices seamlessly into an organization's daily operations, workflows, and employee mindset, making security an inherent part of 'how we do things here.'

  • Focuses on user-centric security design.
  • Emphasizes collaboration over enforcement.
  • Aims to make security an enabler, not a blocker.

Memory trick: Don't just build higher walls; make the gate easy to use and show why it matters.

More Information Security Governance questions