How to establish a Security Awareness program for your Company !
There is no security control which can mitigate or compensate human stupidity. What may seem as common sense to security professionals would be not be so simple for common employees to use and practice. It is therefore essential to incorporate security awareness a part of your security program. Majority of the attacks happening on organisation is due to Social Engineering. By spending effort to train employees to be aware of basic security aspects will help avoid costly mistakes
Common methods of security awareness which can be implemented in an organisation include
- Awareness e mailers
- Online Quizzes
- Phishing Simulations and training
- Training sessions for new joiners
- Compulsory online training for all employees once a year
- Specialized training for developers, system admins , cloud architects, infrastructure specialists and Senior Management
- Awareness weeks twice a year
Themes for Security Awareness
- Privacy of Customer data
- Social Engineering - Physical and against Phishing emails
- Secure Coding for Developers
- Secure practices for Infrastructure team
Details of Awareness week
- Leadership messages
- Online Quizzes
- Games on Floor
- Theme based Skits
- Online Skits
- Posters
- Danglers
- Standees
Security awareness training for third parties such as vendors, contractors and business partners should also be conducted religiously to ensure that they are aware of the security requirements of the organisation.
A annual calendar should be prepared and followed religiously. Additionally key metrics should be defined to ensure that focus on security awareness is maintained throughout the year. The awareness should also be connected with key security risks the business is facing.
Comments
Post a Comment