MIL1 requirements
a. Cybersecurity awareness activities occur, at least in an ad hoc manner
MIL2 requirements
b. Cybersecurity awareness objectives are established and maintained
c. Cybersecurity awareness objectives are aligned with the defined threat profile (THREAT2e)
d. Cybersecurity awareness activities are conducted periodically
MIL3 requirements
e. Cybersecurity awareness activities are tailored to job role
f. Cybersecurity awareness activities address predefined states of operation (SITUATION-3g)
g. The effectiveness of cybersecurity awareness activities is evaluated periodically and according to defined triggers, such as system changes and external events, and improvements are made as appropriate
Our organization has defined procedures for maintaining staff's cyber security awareness.These may include e.g. the following things:
Training should focus on the most relevant security aspects for each job role and include often enough the basics, which concern all employees:
Personnel under the direction of the entire organization must be aware:
In addition, top management has defined ways in which personnel are kept aware of security guidelines related to their own job role.
Ensuring staff security awareness is an important part of protection against malware. Because of this, staff are regularly informed of new types of malware that may threaten them.