官术网_书友最值得收藏!

Methods of conducting training and awareness

As we begin to think about training and awareness, we need to compile the methods we intend on using to conduct outreach:

  • Include specific phishing training as part of your yearly information security training:
    • If you don't conduct yearly training, start
  • Develop a cycle for communicating with your entire user base through an email newsletter:
    • Develop a plan where a certain number of these newsletters are used to deliver targeted phishing awareness training
  • Conduct phishing exercises:
    • Utilize automated tools that allow you to test your user base for their awareness of phishing threats. These tools should allow you to:
      • Import your user population from your user directory instead of manually inputting them into the tool
      • Should allow you to build multiple campaigns so that you can target different user groups at the same time
      • The tools should allow you to track users that get exploited as part of the training so that they can be scheduled for additional training

Users should not be treated negatively if they are determined to need additional training. The process should be positive, and the users should feel that they are learning a new skill instead of feeling that they are being reprimanded.

主站蜘蛛池模板: 光泽县| 随州市| 呼伦贝尔市| 贵德县| 淳化县| 普兰店市| 皋兰县| 增城市| 壤塘县| 新宁县| 巴林左旗| 凤翔县| 德安县| 青神县| 志丹县| 农安县| 安义县| 龙陵县| 个旧市| 嘉峪关市| 若羌县| 股票| 大悟县| 阿合奇县| 平凉市| 二手房| 鄂伦春自治旗| 都江堰市| 麦盖提县| 綦江县| 永泰县| 沁源县| 疏附县| 扬州市| 亚东县| 阿坝县| 绍兴市| 海盐县| 东丰县| 甘洛县| 辰溪县|