Organized Security education, background checks, and other efforts aimed at preventing people within an organization from being part of an attack.
People matter to security, from employees who are targets of social engineering, to architects & engineers who devise and implement security-critical policies.
People management involves preventing these people from becoming part of an attack by:
- helping good actors act well (e.g. education)
- filtering out bad actors (e.g. background checks)
- preventing single points of failure (e.g. limiting intra-departmental communication)
- managing people to help them balance security with other requirements
- liasing between different organizations/divisions to ensure critical information reaches the people who need it.