Security Enablers

Back to previous page

In a series of workshops with critical technology protection, personnel vetting, insider risk/threat, counterintelligence, and physical security disciplines, a major challenge identified by the security community is encouraging new ways to approach security processes, policies, tools, and research. The community noted that organizational guidelines and protocols that enforce policies can seem like an obstacle to process. For example, after policy is introduced, organizations translate that policy into implementation plans, Standard Operating Procedures (SOPs), and Concepts of Operation (CONOPS). At the SOP/CONOP level, personnel tend to perceive approaches to security in one of two manners: “policy will not allow it,” or “how do I enable this securely” (henceforth referred to as the enabler approach). The “policy will not allow it” approach is sometimes necessary to ensure compliance with specific and detailed policies but becomes a problem when it hinders mission-critical processes or organizational progress and improvements. For example, a policy may allow the sharing of sensitive data across government organizations, but SOP-level security implementation may be burdensome or obstructive to the data sharing process itself. Consequently, some individuals may assume these obstacles mean that the process is not allowed or is too burdensome to bother. Meanwhile, an enabler approach can apply security practices to mitigate risk, which facilitates support to activities that would otherwise be considered too risky.

MITRE’s Insider Threat Research and Solutions team led by behavioral scientists sought to understand the enabler approach and underlying perceptions, attitudes, and behaviors. Building from that understanding, the team then built educational and awareness materials to promote and shift workforce attitudes towards enabler-style thinking. Ultimately, this mindset shift will empower the security workforce to identify, understand, and navigate security implementation challenges. Ideally, all employees (regardless of role or seniority) should understand that they can promote new ways to approach security processes, approaches, and tools. This research addresses the strategic effort to support behaviors and attitudes of security community members to be mission enablers of this I&S vision. Notably, the findings from this research have cross-cutting, enterprise-level benefits that reduce institutional barriers, including those that inhibit collective research and development, planning, interoperability, intelligence, and information sharing.

 

 

Back to previous page

Three-pager - Skills-Based Training

One-pager