官术网_书友最值得收藏!

Awareness and training policy

An awareness and training policy provides the foundation for organization-wide cybersecurity communications. The policy should address all levels of the organization from a management (CEO to line employee) and technical (systems, network, database administrator, and so on) perspective. The policy should also address the types of training that the organization will conduct, as well as its recurrence.

An awareness and training policy should address:

  • Ensuring that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems
  • Ensuring that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities
  • Providing security awareness training on recognizing and reporting potential indicators of an insider threat.
主站蜘蛛池模板: 新田县| 广宁县| 靖远县| 微山县| 哈密市| 普定县| 荥经县| 永丰县| 徐州市| 洛扎县| 安化县| 榆树市| 乡城县| 霍州市| 洛宁县| 彭山县| 廉江市| 河间市| 永仁县| 黄浦区| 佛山市| 河西区| 博爱县| 麦盖提县| 繁昌县| 东安县| 马龙县| 西青区| 宜君县| 乐业县| 广宁县| 府谷县| 临沭县| 康平县| 土默特右旗| 四平市| 苏尼特左旗| 赤壁市| 陆河县| 舒兰市| 宝鸡市|