You are on page 1of 4

Security is a Shared Responsibility

Most individuals are not aware of the potential threats and best
practices

The End user behaviour counts

Emphasis on Compliance

To understand expected responsibilities and acceptable behavior

Education program should be tailored as per user roles and


audiences
NIST SETA Model
Security Education Training Awareness
Attribute Why How What

Level Insight Knowledge Information

Objective Understanding Skill Awareness

Teaching Method Discussion, Seminar Lecture, Case Study, Interactive, Video,


Hands-on posters, games

Test Measure Essay Problem Solving True / False or MCQ

Impact Timeframe Long-term Intermediate Short-term


Role Based Awareness Training
• Right training for right peoples

Education Training Awareness

• Executive users • System admins • End users


• System Owner • Tech support • Contractors
• Data Owner
Social Engineering Training

Social EngineeringSocial engineering, in the Employees must be trained on :


context of information security, refers to • How different social engineering attack works
psychological manipulation of people into • What is the primary symptoms of a social engineering attack
performing actions or divulging confidential • Recommended actions
information • Regular testing / contingency exercises

You might also like