Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

User Awareness Training

Posted on 2009-06-30
5
Medium Priority
?
317 Views
Last Modified: 2012-05-07
Hi all, we have just revised our security awareness training programme. In our organisation (small setup) as part of a new starters we give them basic IT security awareness training, i.e. password good practice, awareness for social engineering, shoulder surfing etc.

We have got a 3rd party external audit coming in soon and I wonder what sort of things they will pick us up on. Have you had similar audits, i..e them auditing you that you are training your staff properly. What sort of things did they ask, recommend, highlight in there testing and findings?

In terms of documentation our training programme is documented, we record users attendance etc, we dont allow exceptions i.e. a corporate director still has to have it etc. Anything we are likely to have to do in addition to satisfy the external auditors?
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 18

Expert Comment

by:kjanicke
ID: 24750990
Documentation, awareness, and auditing were key elements in our inspection which was held just a few weeks ago.

If you have a policy of not allowing wireless devices or cell phones in the building, do you actively seek those devices?  If company policy doesn't allow you to surf ebay at work, can you tell who is surfing ebay?  

What types of things do you audit, and do people actually look at the audits?

Proper markings (to the letter) of any regulation you have.  Are portable hard drives encrypted or allowed?

Do you have documented procedures for minor incidents and major disasters?  If you found somebody stealing computer hardware, do the other employees know what to do and who to contact?  Do your employees know where that documentation is?
0
 
LVL 3

Author Comment

by:pma111
ID: 24752181
Thanks kjanicke, what documentation did they ask you specific to training, was it training records or lots more? Regards
0
 
LVL 18

Accepted Solution

by:
kjanicke earned 750 total points
ID: 24752899
They did ask for signed copies of our authorized user policy.  It was some of the basic rules such as sharing passwords, surfing unprofessional web sites, usingt he computer for personal entertainment or profit, etc.

But they also asked how we were preventing or audting the policy.

Having a central location for all documentation helped, but quite a few folks didn't know where it was, and there was almost too much stuff there.  Some documentation wa sn't updated in years.
0
 
LVL 3

Author Comment

by:pma111
ID: 24752904
Thanks ever so much, some good advice. Cheers
0
 
LVL 18

Expert Comment

by:kjanicke
ID: 24757899
Thanks
0

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're a modern-day technology professional, you may be wondering if certifications are really necessary. They are. Here's why.
What we learned in Webroot's webinar on multi-vector protection.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question