CH 7 - Training & Awareness Flashcards
What do Training & Awareness programs do?
1) Communicate privacy policies and procedures,
2) change bad behaviors and
3) reinforce good ones.
What is the difference between training and awareness?
Awareness reinforces lessons learned during training.
What is training?
Communicates the organization’s privacy message, policies and processes, including for data usage and retention, access control and incident reporting, and motivates individuals to retain and follow that information.
Training incorporates measurable outputs and outcomes via attendance and assessment metrics.
Who needs training?
Staff, management, contractors and third parties - anyone who handles personal information on behalf of the organization.
How to engage employees in privacy training?
Use motivators, incentives (e.g., iPad) and even internal competition.
How do accountability obligations apply to training?
Recording who did the training and when.
- Number of training or awareness opportunities by topic
- Number of individuals who enrolled or received awareness communication
- Training method
- Percent of training completed
- Results of quizzes or knowledge tests
- Changes to the number of privacy incident reports or requests for consultation or additional training
Sample training metrics