question archive Part 1: Research Security Awareness Policies (0/1 completed) Note: In this part of the lab, you will review an example of a security awareness training policy in order to form a basis for their purpose and usage
Subject:Computer SciencePrice: Bought3
Part 1: Research Security Awareness Policies (0/1 completed)
Note: In this part of the lab, you will review an example of a security awareness training policy in order to form a basis for their purpose and usage. Understanding the reason behind a security awareness training policy is key to understanding the component policies and procedures. Please take time to review the research thoroughly and think through the concepts of the policy itself.
1. Review the security awareness training policy at the following website:
2. For the sample security awareness training policy that you reviewed in the step above, discuss the policy’s main components. You should focus on the need for a security awareness program and its key elements.
Part 2: Create a Security Awareness Policy (0/6 completed)
Note: A strong security awareness policy is a key component of a strong organizational security posture. The effectiveness of a security awareness training policy and program will directly influence how well employees will value and protect the organization’s security position. When writing a security awareness training policy, consider the following questions:
After the policy has been approved, its success relies on proper delivery and understanding. To simply give a new employee 5 minutes to read and sign a policy during orientation is not enough. Focused and interactive “policy understanding” sessions should guarantee every employee understands the policy’s reasoning and necessity. Customizing these sessions according to department or function can drastically increase how much employees retain of and apply the training during their work. Repeat sessions reinforce the policies and keep material fresh in their minds.
1. Review the following scenario for the fictional Bankwise Credit Union:
2. Create a security management policy with defined separation of duties for the Bankwise Credit Union.
Policy Statement
Define your policy verbiage.
Purpose/Objectives
Define the policy’s purpose as well as its objectives.
Scope
Define whom this policy covers and its scope. What elements, IT assets, or organization-owned assets are within this policy’s scope?
Standards
Does the policy statement point to any hardware, software, or configuration standards? If so, list them here and explain the relationship of this policy to these standards.
Procedures
Explain how you intend to implement this policy for the entire organization.
Guidelines
Explain any roadblocks or implementation issues that you must overcome in this section and how you will surmount them per defined guidelines. Any disputes or gaps in the definition and separation of duties responsibility may need to be addressed in this section.
Challenge Exercise (0/2 completed)Note: The following challenge exercise is provided to allow independent, unguided work - similar to what you will encounter in a real situation.
There are many vendors that provide security awareness training software to organizations that do not have the time nor the resources to create their own. When selecting a software vendor, many organizations will issue a Request for Information (RFI) to potential vendors, outlining the details of what the organization would like to learn about the vendor’s solution. You can read more about RFIs here: https://www.smartsheet.com/free-request-for-information-templates.
As a security manager at eChef, an online marketplace for high-end kitchenware, you have been tasked with selecting a security awareness training software provider.
Use the internet to research real security awareness training software providers.
1.Identify three security awareness training software providers.
2.Identify 10 questions that you would include in your RFI.