Description
Part 1 (Each numbered question must be 150 words or more)
Security awareness training is often the first view a typical user has into information security. Its often required for all new hires. Think of it as the first impression of managements view of information security. This is managements opportunity to set the tone. Most individuals want to do a good job, but they need to know what the rules and expected behavior are. That is one of the purposes of a security awareness policy.
Answer the following question(s):
- What do you think are the two most important practices that should be incorporated into a security awareness policy?
- Why do you rank them so highly?
Part 2
- For each sample security awareness training policy that you reviewed in the step above, discuss the policys main components. You should focus on the need for a security awareness program and its key elements.
- Policy Statement: Define your policy verbiage.
- Purpose/Objectives: Define the policys purpose as well as its objectives.
- Scope: Define whom this policy covers and its scope. What elements, IT assets, or organization-owned assets are within this policys scope?
- Standards: Does the policy statement point to any hardware, software, or configuration standards? If so, list them here and explain the relationship of this policy to these standards.
- Procedures: Explain how you intend to implement this policy for the entire organization.
- Guidelines: Explain any roadblocks or implementation issues that you must overcome in this section and how you will surmount them per defined guidelines. Any disputes or gaps in the definition and separation of duties responsibility may need to be addressed in this section.
Identify three security awareness training software providers. - Identify 10 questions that you would include in your RFI.