Establish and maintain a security awareness program. The purpose of a security awareness program
is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure
manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or
when significant enterprise changes occur that could impact this Safeguard.
The organization has an information security policy developed and approved by top management. The policy shall include at least the following:
In addition, the task owner shall ensure that:
The organization enhances security culture by developing comprehensive training materials, requiring onboarding and annual refresher training, and customizing sessions by role and department. It regularly updates training content, and tracks participation to ensure compliance and accountability.
A log is kept of the cyber security training events provided by the organization to its staff. The log can be used to show what kind of specific investments the organization has made towards staff's cyber security expertise.
For each training the documentation should include: