Security Education, Training, and Awareness

Security education builds awareness, reinforces best practices, fosters a culture of vigilance, and equips individuals to recognize, report, and respond effectively to threats.

5 slides · 5 min read · Domain 6

Slide 1

The security environment is rapidly

New technologies, systems, and controls changing, with new threats emerging require specific knowledge to ensure they daily. Modern systems and applications are are properly configured and used. Most increasingly distributed, rely on virtualized enterprise organizations have training environments, and demand collaboration programs to support their business needs. across diverse organizations to ensure their Awareness programs are more general in proper, secure operation. This dynamic nature than training. NIST SP 800-50, Rev.

landscape requires ongoing investment in 1—Building a Cybersecurity and Privacy education, training, and awareness. Security

Learning Program distinguishes between education, training, and awareness (SETA) the two activities. Training teaches specific activities each address different aspects of skills, concepts, knowledge, and attitudes this challenge.

necessary to perform a job, while awareness Education presents a body of knowledge focuses on recognizing threats, avoiding that students can apply to a broad range risky behaviors, and acting wisely to of problems. However, the rapid pace increase cybersecurity. of change in the information security Major security frameworks call for field challenges traditional educational integrating SETA programs into an models, as that body of knowledge evolves organization's security practice. FIPS 200 quickly. As a result, education for security identifies the Awareness and Training (AT) professionals cannot end once their formal control family as the umbrella for a set of training is complete. controls that organizations must address ISC2 members must continue their to comply with the standard. According to education to maintain their credentials. ISO 27001:2022 on information security Fortunately, busy security professionals management systems, all employees should have many ways to stay current and sharpen receive information security training and their skills: attending in-person or virtual awareness, along with regular updates on seminars and conferences, completing organizational policies and procedures. self-paced courses, following current

self-paced courses, following current perspectives and analysis in the field, and pursuing formal academic programs.

The ISC2 Professional Development Institute (PDI) enables credential holders to continue their professional education in the latest technologies, trends, and challenges facing the security profession.

Training activities focus on specific knowledge acquisition to perform a task.

The structure, development, priorities, and efficacy of a SETA program is entirely dependent on the organization's policy and strategy. An initial and continuous needs assessment helps determine an organization's awareness and training needs and can convince management to allocate adequate resources for the program.

At a minimum, consider the following roles

  • System administrators and IT support for special training needs: personnel. Entrusted with high authority over support operations
  • Executive management. Organizational

critical to a successful security program, leaders need to fully understand these individuals need more technical directives and laws that form the basis knowledge in effective security

for the security program. They also need

practices and implementation.

to comprehend their leadership roles in ensuring full compliance by users within

  • Operational managers and system their units. users. These individuals need a high degree of security awareness and
  • Security personnel (security program

training on security controls and rules managers and security officers). These of behavior for systems they use to individuals act as expert consultants conduct business operations. for their organization. They must be well educated about security policy and The question to be answered when accepted best practices. beginning to develop material for a specific training course is, "What skill or skills do we

  • System owners. Owners must have a

want the audience to learn?" The awareness broad understanding of security policy and training plan should identify an and a high degree of understanding

audience, or several audiences, that should

regarding security controls and receive training tailored to address their IT requirements applicable to the security responsibilities. systems they manage.

There are various security awareness sources that can be incorporated into an awareness program. The material can address a specific issue or, in some cases, describe how to develop an entire awareness program, session, or campaign. Sources of timely material may include the following:

  • Email advisories issued by industryhosted news groups, academic institutions, or the organization's IT security office
  • Professional organizations and vendors
  • Online IT security daily news websites
  • Periodicals
  • Conferences, seminars, and courses

Awareness material can focus on one theme or combine several. For example, an effective awareness poster might carry a single message, such as "Think before you click," while an instructor-led or web-based session provides deeper learning, such as understanding risks and critically evaluating online content. Regardless of the approach, the amount of information should not overwhelm the audience.

A typical awareness presentation touches on the requirements (policies), the problems the requirements were designed to remedy, and the actions one should take.

Evaluating a program's real success is challenging. High attendance numbers don't necessarily reflect behavioral changes. To truly quantify the impact, innovative approaches are needed.

Integrating phishing campaigns into an organization's workflow by sending phishing emails to users and tracking who responds is a common example of such an approach.

Successful SETA programs have meaningful evaluation measures that demonstrate SETA program effectiveness. The evaluation programs' results are used for various purposes, including retraining and program reevaluation. As with all controls, continuous process improvement methods should be used to maintain training and awareness relevance, cultural change, compliance, and impact.

Test this domain