You can't configure your way to systems security. Passwords are a perfect case in point. Windows has five separate policy settings designed to force users to select hard-to-guess passwords—and a determined user can overcome every one of them if he or she is hell-bent on having a weak password. Similarly, firewalls, intrusion prevention systems, and vulnerability scanners won't compensate for negligence on the part of users or administrators. That's why a security awareness program is a crucial component in any organization's information security strategy. Even small businesses need to give attention to security awareness. Without a solid program in place, your legal liability increases, and your legal recourse against dishonest employees is weakened. But aside from legal matters, without a security awareness program, you face greater risk in general, and the return on your security-related investments is diluted. Let's look at the major elements of a security awareness program, and I'll offer suggestions for running one successfully. . . .