Khi nhóm đánh giá làm việc với khách hàng để điền vào OICM, đó là bình thường cho các khách hàng muốn thay đổi một số điều. Hãy nhớ rằng ma trận này không phải là tĩnh. Bạn có thể thay đổi nhiều mục nhiều lần trong quá trình này. Các khách hàng nên được kiểm soát bởi vì họ hiểu kinh doanh của họ. | 154 Chapter 5 The System Security Environment Understanding the Cultural and Security Environment Understanding the cultural and security environment involves more than understanding the location of the room that contains the components that process store or transmit an organization s critical information. As the INFOSEC assessor you need to understand the operational culture and security environment that houses the critical information. Terminology Alert__ The cultural environment is made up of the people who work in that environment and their perceptions of how things are done or should be done. The culture of the organization can and does vary with the people in the environment. It includes customer perceptions of their requirements and how those requirements apply to the organization. This information leads to identification of the security environment. Terminology Alert_ The security environment is made up of the documented requirements for operations. The requirements can be in the form of legal requirements and official and unofficial policy. Defining the customer s perceived environment depends on the applicable laws regulations and architecture. Few laws or regulations apply to all as the assessor must understand the appropriate regulations to facilitate the definition of the security environment. The Importance of Organizational Culture The organization s culture is important. Recommendations that you make should fit the organization s operational requirements. We are all aware that security is The System Security Environment Chapter 5 155 usually seen as a hindrance to work. Many people distrust any implementation that is security related. Many aspects of the organization s environment define the culture and need to be identified. The organization s culture depends on many factors including employees personal backgrounds education .