Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Becoming a Security Culture Practitioner
Articles

Becoming a Security Culture Practitioner

ISBuzz TeamBy ISBuzz TeamSeptember 12, 2014Updated:April 30, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Earlier this summer, the Security Culture Framework Summer Camp successfully completed its first iteration, leaving students with a deeper understanding of the importance of security culture and how each and every organization should treat awareness programs as a priority.

(NOTE: This is the second article of a two-part series. Please click here to read the first part.)

The summer camp was structured around the Security Culture Framework (SCF), a learning template developed by Kai Roer of the Roer Group. Roer first created the SCF to teach information security professionals how to develop unique activity campaigns that could be used to strengthen their organization’s security cultures. Since that time, Roer has traveled the world, leading countless conferences and workshops on how professionals can implement the SCF at their workplace.

FREE Download: CISO Data Breach Guide

As evidenced by its international appeal, the SCF is fundamentally an adaptable process. It does not assume that all organizations’ security needs are the same. As a result, the Security Culture Framework serves as a valuable resource regardless of where or for whom security professionals work.

The SCF is made up of four elements: metrics, organization, topics, and planner. Roer designed the class in such a way that each component received one week of instruction, including lectures, videos, and a written assignment. In this way, students learned the SCF incrementally, allowing for greater synthesis of knowledge.
[wp_ad_camp_4]
This article focuses on the second half of the course, during which we learned about the topics and planner elements. For the former, we investigated a variety ways organizations can enhance their security culture. We were then tasked with developing activities that could help augment our own organizations’ security culture. This was probably the least difficult assignment in the course. In order to complete our first assignment, which dealt with metrics, we had to consider how we could measure improvement with regards to certain security goals we set for ourselves. Deciding on our goals inevitably required some thought into what kinds of activities we could employ, so I drew from this prior experience to create an in-depth anti-phishing campaign. Looking up phishing simulation software, not to mention traditional posters and hand-outs, was actually quite fun. I could see everything in the course beginning to fall into place, and comparing prices helped me begin budgeting my expenses. In hindsight, I feel the topics session would have worked well at the beginning, possibly by being partnered with the metrics unit.

Once we chose all of our activities, we were then ready to learn about the final element: planner. In this section of the class, we learned about how organizations successfully schedule and time-manage different security campaigns, or a finite set of complementary security culture activities. Our final assignment challenged us to do just that. Not only were we required to figure out how our activities would blend together, but we were also charged to assign different parts of the process – such as formulating our core teams, running the activities, and recording our results – discrete dates. This level of detail ultimately emphasized the real-world applicability of our efforts.

The planner assignment was our “final exam.” After we submitted all of our written work for the course, Roer and his associate Mo Amin looked over our assignments and awarded certificates of completion shortly thereafter.

I am grateful that I had an opportunity to participate in The Security Culture Framework Summer Camp this year. Challenging the idea of the “human factor,” the course taught me a great deal about how an educated human user can actually enhance an organization’s security. No two persons could have conveyed this point better than Roer and Amin. Their witty banter in our Google Hangouts, not to mention their accessibility over email, made this course the particularly enjoyable experience that it was.

Summer is over, but so what? Training knows no season. I invite you to visit the Security Culture Framework website to learn more about Roer’s creation. From there, check out this page that hosts available educational resources offered by the Roer Group. Who knows? Maybe another SCF camp is right around the corner.

David Bisson | @DMBisson

david_bissonDavid is a graduate of Bard College, having received a B.A. in Political Studies. He is very interested in cybersecurity and completed his senior thesis on the U.S. military’s integration of cyber power. Currently, he works as the Editor for Information Security Buzz and the Media Coordinator at the Hannah Arendt Center for Politics and Humanities at Bard College. Going forward, David would like to leverage his extensive journalism experience as well as his interest in computer coding and social media to pursue a career in cyber security, both its practice and policy

security_awareness

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}