Chapter 8 - Sustain - Training And Awareness Flashcards
What is the average cost of a data breach as of 2020
3.86 million dollars
What are the top three industries in terms of financial impact of a data breach
1 healthcare (7 million)
2. Energy (6 million)
3. Financial services (5 million)
What can be done to reduce the cost of a data breach
Have an information security and incident response team in place (can reduce costs by 2 million)
What is the difference between training and awareness?
Training strives to produce relevant and
needed skills and competencies. Awareness focuses on a specific topic, such as security. Awareness is intended to allow individuals to recognize specific concerns, such as technology, and respond accordingly.6
What is NIST SP 800-50
NIST SP 800-50, “Building an Information Technology Security Awareness and Training Program,”
What are the 4 steps in the NIST 800-50 awareness and training life cycle
- Awareness and training program design
- Awareness and training material development
- Program implantation
- Post implementation