10: 7 Security Awareness and Training Flashcards
Security Training
Provides users with knowledge they need to protect the org’s security
Security Awareness
Keeps the lessons learned during security training top of mind for employees
Security Training Methods
On-site classes, integration with orientations, education through online providers
Diversity of training techniques
Gamification, phishing simulations, capture the flag
Customized training
Based upon user roles and their role requirements
Training Frequency
Balancing time and job responsibilities - can use initial training and major updates with awareness campaigns
Password training
Secure password practices should be included in training
Data handling procedures
Policies for handling and destroying data should be included in training
Acceptable Use Policy
Remind users of organization’s rules and actions it’ll take if the policy is violated