inflearn logo

Planning information security and personal data protection events/campaigns

The purpose is to improve, compared with last year, awareness campaigns that are not defined in the regulations and often end merely with the distribution of promotional gifts, by referring to best practices from various organizations, given the current situation in which the performance of events and campaigns such as Information Security Day or Personal Information Protection Day, held monthly or annually, is gradually declining. These events must now move beyond gift-distribution activities organized by the Information Security Team and become events in which all employees participate and uphold security together. It is necessary to build mutual understanding through the establishment of a communication system for embedding security into the organization. Ultimately, employees must have a good understanding of information security and the Personal Information Protection Act so that the organization can realistically protect itself from hacking and insider threats. Since the departments other than the Security Team—including those responsible for commissioning various projects, managing entrusted service providers, controlling applications and security settings, planning various informatization projects, and conducting IT audits—are designated to take overall responsibility, the Security Team is distributing security-related tasks among the respective departments. However, the current situation is that each department is merely expressing dissatisfaction. This opportunity should therefore be used to move away from that situation, as internal consultative bodies alone are insufficient. Security-related scoring criteria must be reflected in the powerful personnel evaluation system. Through unannounced audits, those who fail to comply should be disciplined through pay reductions or suspension, while those who properly observe security requirements and demonstrate achievements in support of security should receive substantial financial rewards through an incentive system. Security must be embedded in the organization so that employees take the initiative themselves. Accordingly, department and individual evaluation KPIs should be adjusted through a report to the CEO under the direction of the CISO. In addition, through a system for designating department-level information security officers and personnel in charge, the organization should strengthen its human security framework against hacking and information leakage—including the leakage of documents managed by each department and the management of service providers—by providing position allowances for these responsibilities.

1 learners are taking this course

Level Beginner

Course period 6 months

AI
AI
security training
security training
Engineer information security
Engineer information security
ISMS-P
ISMS-P
AI
AI
security training
security training
Engineer information security
Engineer information security
ISMS-P
ISMS-P

News

No published news.

Limited time deal

$3.30

25%

$4.40