Published: 13 September 2023
Managing the Human Factor in Information Security by David Lacey
“Risk management will always be a major challenge. It’s an unusual blend of logic and feeling, with the latter dominating the former. And most people are bad at assessing risks. They have different perceptions, shaped by their personality, experience, culture and other influences.
Information security is a long-term journey. The starting point is to develop a clear vision of what needs to be achieved, and a strategy setting out how we intend to get there. Everybody needs a structure for their work, but its important not to become distracted and lose sight of our real objectives. Frameworks and architectures are a means to an end, not an end themselves.”
The Bailiwick of Guernsey's independent supervisory authority which regulates data protection legislation. The ODPA protects people by driving responsible use of personal information through helping organisations get it right, deterring harmful information handling, and taking enforcement action against significant non-compliance
Receive regular information and statistics related to our activities and governance
Sign up nowReceive regular information and statistics related to our activities and governance
Sign up nowThe Office of the Data Protection Authority
+44 (0)1481 742074 info@odpa.gg
Block A, Lefebvre Court, Lefebvre Street, St Peter Port, GY1 2JP
Newsletters sign-up Data Processing Notice Careers Cookies
Website by
&
Indulge
© 2025 The Office of the Data Protection Authority.