官术网_书友最值得收藏!

Awareness and training policy

An awareness and training policy provides the foundation for organization-wide cybersecurity communications. The policy should address all levels of the organization from a management (CEO to line employee) and technical (systems, network, database administrator, and so on) perspective. The policy should also address the types of training that the organization will conduct, as well as its recurrence.

An awareness and training policy should address:

  • Ensuring that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems
  • Ensuring that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities
  • Providing security awareness training on recognizing and reporting potential indicators of an insider threat.
主站蜘蛛池模板: 瓮安县| 剑川县| 怀集县| 张家界市| 镇赉县| 张家界市| 正宁县| 佛教| 台中市| 福泉市| 朝阳市| 信阳市| 枣庄市| 兴宁市| 喀喇| 尖扎县| 思南县| 四平市| 渝中区| 康乐县| 汝城县| 罗田县| 乡宁县| 汝州市| 阿瓦提县| 偃师市| 建湖县| 阜宁县| 沅江市| 黄陵县| 宜兴市| 隆昌县| 内乡县| 濮阳县| 宽城| 灵武市| 永城市| 黄梅县| 遂川县| 陆丰市| 隆林|