8. Operations: Training and Awareness Flashcards
What risk mitigating tests can incident response teams preform?
- Incident response testing
- Red team testing
- Threat intel sharing
- Data loss prevention
What accounts for 67% of data breach events?
Credential theft, social attacks (phishing), business email compromises, and administrative errors.
Are the majority of incidents internal or external?
70% are external
What is the most common method of breach attack?
Attacking web applications through stolen credentials (80%) or brute force credentials
What is the difference between training and awareness?
Training - strives to produce relevant and needed skills and competencies
Awareness - focuses on a specific topic such as security
*NIST SP 800-50: “The most significant difference between training and awareness is that training seeks to teach skills, which allow a person to preform a specific function, while awareness seeks to focus an individual’s attention on an issue or set of issues”
Is training a regulatory requirement?
Yes, it is a key control with most privacy regulations.
What must privacy training address?
- Applicable laws and policies
- Identify potential violations
- Address privacy complaints and misconduct
- Include proper reporting procedures and consequences for violations
To whom internal training extend to?
Business partners and vendors.
What should trainees be required to acknowledge?
That they received training and agree to abide by company policies and applicable law.
What functions do training and awareness serve?
Training - communicates the organizations privacy message, policies and procedures, including those for data usage and retention, access control and incident reporting
Awareness - reinforces the privacy message through reminders, continued advertisement, and mechanisms such as quizzes, posters, flyers, and lobby video screens
What should be considered when privacy breaches occur?
- Leverage lessons learned from events that make the headlines
- Use mistakes as learning opportunities to improve process
- Use stories
- Hold lunch and learn sessions
- Make it fun
- Develop slogans that can be used in presentations to capture the essence of the message
What methods can lead to the development and execution of an effective training and awareness plan?
- Ingrain operational accountability
- Ensure a holistic data protection view
- Allow for the incorporation of compliance requirement changes
- Identify, catalog, and maintain all document requirements update as privacy requirements change
What is the most effective targeted training effort?
Where the privacy office spends time with the business unit’s leader to learn about risk areas and modifies the training or presentation accordingly.
What should the intention behind training and awreness?
Changing bad behaviours and reinforcing good ones.
What are some training and awareness methods?
- Formal education
- E-learning
- Brown bag and department team meeting
- Newsletters, emails, and posters
- Handouts
- Slogans and comics
- Internal social media page
- Webpages
- Hallways or lobby monitors to broadcast
- Contests