- Information Security Handbook
- Darren Death
- 139字
- 2021-07-02 21:55:56
Awareness and training policy
An awareness and training policy provides the foundation for organization-wide cybersecurity communications. The policy should address all levels of the organization from a management (CEO to line employee) and technical (systems, network, database administrator, and so on) perspective. The policy should also address the types of training that the organization will conduct, as well as its recurrence.
An awareness and training policy should address:
- Ensuring that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems
- Ensuring that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities
- Providing security awareness training on recognizing and reporting potential indicators of an insider threat.
推薦閱讀
- CSS全程指南
- 自動檢測與轉換技術
- 塊數(shù)據(jù)5.0:數(shù)據(jù)社會學的理論與方法
- 中國戰(zhàn)略性新興產(chǎn)業(yè)研究與發(fā)展·工業(yè)機器人
- 面向對象程序設計綜合實踐
- Red Hat Linux 9實務自學手冊
- Azure PowerShell Quick Start Guide
- HTML5 Canvas Cookbook
- Photoshop行業(yè)應用基礎
- Machine Learning with Spark(Second Edition)
- Learn Microsoft Azure
- 實戰(zhàn)Windows Azure
- 樂高創(chuàng)意機器人教程(中級 上冊 10~16歲) (青少年iCAN+創(chuàng)新創(chuàng)意實踐指導叢書)
- 網(wǎng)絡安全概論
- Mastering MongoDB 4.x