Part 1: Attitudes About Security
Which of the following attributes generally apply to your security program?

(Select zero if the statement doesn't apply, and nine if it always applies.)
1.
There is widespread arrogance and overconfidence about the security program.

0

1

2

3

4

5

6

7

8

9



2.
Security is viewed as binary--things are thought to be either secure or not secure.

0

1

2

3

4

5

6

7

8

9



3.
Security department is focused on paperwork, auditors, regulations, standards and compliance.

0

1

2

3

4

5

6

7

8

9



4.
Insiders are not viewed as a threat.

0

1

2

3

4

5

6

7

8

9



5.
VIPs are allowed to bypass standard security procedures.

0

1

2

3

4

5

6

7

8

9



6.
Security is micromanaged by business executives who lack adequate knowledge of security.

0

1

2

3

4

5

6

7

8

9



7.
Serious vulnerabilities are assumed not to exist. Comprehensive vulnerability assessments are rare and don’t result in substantial changes.

0

1

2

3

4

5

6

7

8

9



8.
Security managers rarely “walk the spaces” or chat informally with nonsecurity employees.

0

1

2

3

4

5

6

7

8

9



9.
Technology is viewed as a silver bullet for security

0

1

2

3

4

5

6

7

8

9