Privacy Operational Life Cycle: Chapter 8 Sustain: Training Flashcards
Incident Response team (Cost mitigation)
Incident response testing
Red team testing
Threat intel testing
Data loss prevention
Cost contributers
Non-efficient controls
Lack of qualified cyber security staff
Complex security systems
Training
produce relevant and needed skills and competencies
Focus on teaching
Awareness
allow individuals to recognize specific concerns and respond accordingly
Focus on issues
NIST SP 800-50
training framework for infosec
Training must:
Address applicable laws
Identify potential violations
Address privacy complaints and misconduct
Proper reporting procedures and consequences for violating laws
Require acknowledgement
Awareness program
Reminders
Advertisements
Quizzes
Posters and flyers
Video boards