October is National Cyber Security Awareness Month! Some quick links to get you started...
- Read this blog post so you don't have to start your plans from scratch! Let's Get Ready for NCSAM 2015.
- View related resources including the NCSAM Sample Kit, Cybersecurity Awareness Resource Library, Security Awareness Quick Start Guide, and Security Awareness Detailed Instruction Manual.
- Find a guest speaker using our Speakers Bureau.
- Get involved in the Stop.Think.Connect. awareness campaign.
- Become a NCSAM Champion. It's free and easy to sign up. You'll also find free materials at StaySafeOnline.org, including this handy "Ways to Get Involved" infographic.
- Data Privacy Day occurs each year on January 28. Think about how you might use NCSAM resources to promote this international celebration on your campus, too. (Details about 2015 activities will be available in the fall.)
We are currently updating the list below with 2015 activities. Please let us know about your campus plans! (In 2014, over 200 higher education institutions hosted NCSAM campus events!)
Also on this page: What is Cyber Security Awareness?, Why is Cyber Security Awareness Important?, Critical Success Factors for Awareness Activities, What is National Cyber Security Awareness Month?, How Do We Plan for NCSAM?, and additional Resources (including links to state/regional and international efforts).
2015 Campus Events
In 2014 we found over 200 campuses supporting NCSAM with activities and events! We are currently collecting URLs or plans for your 2015 NCSAM-related initiatives. You can send a message to the Security Discussion Group or send us an e-mail directly: security-council@educause.edu.
- Cal Poly Pomona: Hosting the 10th annual Cyber Security Fair with the theme "Trick or Treat: Why Your Choices Matter" and an emphasis on women in cybersecurity. (October 29, 2015 in Pomona, CA)
- University of Virginia: Hosting the 12th annual VASCAN Conference with the theme "They Will Get In. What Are We Doing About It?". (October 1-2, 2015 in Charlottesville, VA)
What is Cyber Security Awareness?
The Oxford English Dictionary defines awareness as "The quality or state of being aware; consciousness." Aware is defined as "Informed; cognizant; conscious; sensible."
The purpose of cyber security awareness presentations is simply to focus attention on cyber security. Awareness presentations are intended to allow individuals to recognize information technology security concerns and respond accordingly.
- The learner is the recipient of information
- The information reaches broad audiences
- Attractive packaging techniques are used
We can characterize a user's cyber security awareness level by describing it as the actions a user takes in a given security situation. Do they know about any policies governing that activity? Do they follow the policy? What happens when they are confronted by a new situation that is not addressed by the policy?
Why is Cyber Security Awareness Important?
To protect the confidentiality, integrity, and availability of information in today's highly networked systems environment requires that all individuals:
- Understand their roles and responsibilities related to the organizational mission
- Understand the organization's information technology security policy, procedures, and practices
- Have at least adequate knowledge of the various management, operational, and technical controls required and available to protect the IT resources for which they are responsible
Cyber security awareness programs impress upon users the importance of cyber security and the adverse consequences of its failure. Awareness may reinforce knowledge already gained, but its goal is to produce security behaviors that are automatic. The goal is to make "thinking security" a natural reflex for everyone in the organization. Awareness activities can build in these reflexes both for the security professional and for the everyday user.
Critical Success Factors for Awareness Activities
- They are based on the organization's policies
- They have senior management support
- The focus is on people at all levels of the organization
- They are effectively planned:
- Based on user's needs, roles, and interests
- Identifies security problems in the organization that need addressing
- They use appealing materials and methods
Awareness programs usually use repetition to reinforce desired behaviors and attitudes about security.
What is National Cyber Security Awareness Month?
National Cyber Security Awareness Month is an annual effort to increase awareness and prevention of online security problems, spearheaded by the U.S. Department of Homeland Security and the National Cyber Security Alliance (NCSA). The Higher Education Information Security Council (HEISC) promotes and participates in the annual campaign each October, joining forces with a range of organizations from the public and private sector to expand cybersecurity awareness on campuses across the country. The Higher Education Information Security Council is offering a range of programs and resources:
- NCSAM Resource Kit and NCSAM Sample Kit
- Information Security Awareness Video & Poster Contest for Students
- Cybersecurity Awareness Resource Library
- EDUCAUSE Security Awareness Resource Page
How Do We Plan for National Cyber Security Awareness Month?
The following worksheet will help you to think about how your institution might go about implementing a plan to take advantage of National Cyber Security Awareness Month.
Indiana University offers a NCSAM Sample Kit with creative materials based on a 1950's horror theme, and outlines plans for their use that you can adapt to your institution's needs quickly. With a bit of a printing budget (or your own high quality printer) and some coordination, you can pick and choose which materials will best help you to increase your community's security awareness. Some of the materials are even provided in Spanish! These materials were created and used at Indiana University for National Cyber Security Awareness Month 2005. Indiana University grants permission for non-profit educational use, as long as the credit line and the copyright statement remain on the materials.
Cal Poly Pomona's 2007 presentation describes the development of their Cyber Security Fair in great detail. Tips for starting your own cyber security fair are offered on such topics as determining the target audience, structuring the event, developing a support network, selecting presentation topics & speakers, as well as the associated costs.
The winning posters and videos from previous Information Security Awareness Video & Poster Contests are available for use in campus security awareness campaigns during student orientation, National Cyber Security Awareness Month, Data Privacy Month, and throughout the year. Note: Videos are also available to view on the Security Awareness Contest YouTube Channel. Posters can be found on the contest's Facebook page or the HEISC Pinterest page.
If your group or institution would be interested in a presentation from an information security or privacy expert, please see our Speakers Bureau. You could also use your LinkedIn connections to invite a local, regional, or national speaker to a campus event.
Resources
- "Building an Information Technology Security Awareness and Training Program," National Institute of Standards and Technology Special Publication 800-50, Oct. 14, 2003
- "Developing Security Education and Awareness Programs" by Shirley Payne
- DHS Stop.Think.Connect. campaign and Online Toolkit & Campaign Materials
- Indiana University National Cyber Security Awareness Month Campaigns and Downloadable Material
- MS-ISAC (Multi-State Information Sharing and Analysis Center) National Cyber Security Awareness Month Toolkit (2013)
- NCSA Resources (2012)
- Presidential Proclamation: National Cybersecurity Awareness Month (2012)
- SANS Securing The Human security awareness program
State and Regional Efforts
- Community Based Security Awareness - Various Efforts
- MS-ISAC list of State and Local Government Proclamations
- NASCIO Cybersecurity Awareness Resource Guide
- State of California (2012)
- State of New York (2012)
- State of Pennsylvania (2012)
International Efforts
- Australia: National Cyber Security Electronic security, or online security. Awareness Week is an annual Australian Government initiative held in partnership with industry, community and consumer organizations and all levels of government.
- Canada: Get Cyber Safe is Canada's national public awareness campaign on cyber security
- South Africa: The Cyber Defence Research Group of the Council for Scientific and Industrial Research (CSIR) hosts a serices of talks on cyber security awareness-related topics
Questions or comments? Contact us.
Except where otherwise noted, this work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License (CC BY-NC-SA 4.0).