1.13 Establish and Maintain A Security Awareness, Education, and Training Program Flashcards
Who is Responsible for Security?
Everyone!
How can a company ensure all employees understand their security responsibilities?
Through ongoing awareness, training, and education.
What is the goal of fostering Awareness in an organization?
To create cultural sensitivity to a given topic or issue.
What are ways organizations can promote awareness of security responsibilites?
Phishing campaigns, lunch and learns, and awareness posters.
What is the purpose of Training?
To provide specific skills needed to perform a task related to security. This includes phishing campaigns, firewall admin training to configure firewall rules, and security officer training to handle specific situations.
What does Awareness Do? Who is Responsible?
Raises cultural awareness and sensitivity to a topic | Organization wide without much dedicated time involved.
Why is Training useful?
Provides more specific technical skills and focuses on specific skills related to security-focused tasks/roles.
What is Education good for?
Focusing on fundamental concepts and developing decision-making skills.
How can you ensure Awareness is conveyed effectively to the entire organization?
Use language specific to the audience such as live in-person sessions, requirements/rewards, regular campaigns, etc.
What source can be used to identify the most important topics security awareness, training, and education should focus on?
The organization’s Risk Register | This helps organizations ensure their most valuable and at-risk assets are receiving proper attention and training.
Why use Periodic Content Reviews?
To ensure that awareness, training, and education program materials are evolving alongside the rapidly changing threat landscape.
What are some Key Metrics to consider when tracking awareness, training, and education program effectiveness?
Total number of people completing the program | Number of people providing feedback compared to total attendees | Number of people reporting suspicious activities after training is complete | Tracking how well staff members performed (Passing scores ranges, etc.) | Total number of attempts the course was taken by each person