Skip to main content
Guidance

Cyber security culture principles

How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.

Page 7 of 10

Principle 6. Provide well-maintained cyber security rules and guidelines, which are accessible and easy to understand

Gremlin via Getty Images

Establishing rules and guidelines to create a cyber secure workplace requires a careful balance. The rules need to allow people the flexibility to work and solve problems within their local areas, but they also need to set expectations that everyone knows and respects. Done well, they help establish a trusted relationship between the organisation and its people. 

Having rules which are too prescriptive will eventually be detrimental to security, as they will rapidly become unwieldy and outdated. On the other hand, guidance that is too casual or vague leaves people in the dark and exposed to risks that they are ill-equipped to manage. Both approaches can cause uncertainty and stress and could deter people from engaging further with cyber security. 

Achieving this balance means engaging with different areas to learn where they are struggling, inviting stakeholders from these groups to contribute to rule development, listening to feedback and regularly reviewing and testing whether they are serving their purpose.

The rules and guidelines should be embedded in processes and onboarding and must be easy to find and reference, and make it clear when updates supersede any earlier content. If the rules or guidelines for any process are unclear, missing – or ineffective in certain situations – and people don’t know how to manage the security risks, then they should have quick and easy access to experts to help them.

What good looks like

  • You have tested every cyber security rule to ensure it makes a meaningful contribution to the security of the organisation, is usable and accessible by everyone, and aligns with the shared purpose. 

  • Your cyber security rules and guidelines are designed for inclusivity, are easy to find and access, and are included in onboarding materials.

  • People understand the difference between the rules that must be followed and the guidelines that provide advice.

  • You invite and use people’s feedback to continue to refine and improve your security rules.

  • You widely communicate any changes to rules and ensure out of date material is archived to avoid confusion.


Published

Reviewed

Version

1.0