- Security awareness
Security awareness is the knowledge and attitude members of an organization possess regarding the protection of the physical and, especially, information assets of that organization. Many organizations require formal security awareness training for all workers when they join the organization and periodically thereafter, usually annually.
Topics covered in security awareness training include:
*The nature of sensitive material and physical assets they may come in contact with, such as
trade secret s,privacy concerns and governmentclassified information *Employee and contractor responsibilities in handling sensitive information, including review of employee nondisclosure agreements
*Requirements for proper handling of sensitive material in physical form, including marking, transmission, storage and destruction
*Proper methods for protecting sensitive information oncomputer systems, includingpassword policy and use oftwo-factor authentication
*Other computer security concerns, includingmalware ,phishing ,social engineering , etc.
*Workplace security, including building access, wearing of security badges, reporting of incidents, forbidden articles, etc.
*Consequences of failure to properly protect information, including potential loss of employment, economic consequences to the firm, damage to individuals whose private records are divulged, and possible civil and criminal penaltiesBeing Security Aware means you understand that there is the potential for some people to deliberately or accidentally steal, damage, or misuse the data that is stored within our computer systems and through out our organization. Therefore, it would be prudent to support the assets of our institution (information, physical, and personal) by trying to stop that from happening.
According to [http://www.enisa.europa.eu/ ENISA] 'Awareness of the risks and available safeguards is the first line of defence for the security of information systems and networks.'
'The focus of Security Awareness consultancy should be to achieve a long term shift in the attitude of employees towards security, whilst promoting a cultural and behavioural change within an organisation. Security policies should be viewed as key enablers for the organisation, not as a series of rules restricting the efficient working of your business.'
ee also
*
Access control
*Physical Security
*Security
*Security controls
*Security management
*ISO/IEC 27002 ----
Web Sites Providing Security Awareness Programs
[http://www.inspiredelearning.com/sat/default.htm Inspired eLearning] - 10 course online Security Awareness training program plus posters, screensavers, and a monthly eNewsletter
[http://www.SCIPPinternational.org SCIPP International] - Not-for-Profit On-line Security Awareness and Certification Services
[http://www.eLearningCorner.com eLearning Corner] - Security Awareness training for employees
[https://www.nationaldigitalservices.com/ National Digital Services]
[http://www.nativeintelligence.com Native Intelligence] - Security Awareness Courses, Posters, Daily Tips
Wikimedia Foundation. 2010.