官术网_书友最值得收藏!

Methods of conducting training and awareness

As we begin to think about training and awareness, we need to compile the methods we intend on using to conduct outreach:

  • Include specific phishing training as part of your yearly information security training:
    • If you don't conduct yearly training, start
  • Develop a cycle for communicating with your entire user base through an email newsletter:
    • Develop a plan where a certain number of these newsletters are used to deliver targeted phishing awareness training
  • Conduct phishing exercises:
    • Utilize automated tools that allow you to test your user base for their awareness of phishing threats. These tools should allow you to:
      • Import your user population from your user directory instead of manually inputting them into the tool
      • Should allow you to build multiple campaigns so that you can target different user groups at the same time
      • The tools should allow you to track users that get exploited as part of the training so that they can be scheduled for additional training

Users should not be treated negatively if they are determined to need additional training. The process should be positive, and the users should feel that they are learning a new skill instead of feeling that they are being reprimanded.

主站蜘蛛池模板: 商都县| 仪征市| 南昌市| 建德市| 塔河县| 常山县| 珲春市| 虹口区| 新余市| 泰顺县| 台湾省| 罗平县| 临西县| 博野县| 鲁山县| 泽普县| 邵东县| 天津市| 隆德县| 普定县| 西藏| 应城市| 铁力市| 德令哈市| 滨海县| 石泉县| 拜泉县| 忻城县| 崇州市| 琼海市| 红河县| 阿坝县| 嵊州市| 独山县| 济源市| 珠海市| 香格里拉县| 天长市| 德州市| 安阳市| 高淳县|