|
|
|
Training Information Security
training is the KEY STONE to a good security posture. Every security incident
investigated from either inside or outside a corporation can be traced back to
a lack of security training. A good Security training program can reduce loss,
corruption, degradation and misuse of data and resources within a corporation.
The Computer Security Act of 1987 required federal
agencies to provide for mandatory periodic training in computer security
awareness and accepted computer practices of all employees who are involved
with management, use, or operation of each federal computer system within or
under the supervision of that agency. The scope and goals of federal computer
security awareness and training programs must implement this broad mandate.
(Other federal requirements for computer security training are contained in OMB
Circular A-130, Appendix III, and OPM regulations.) Level of Training
Required for a Complete Security Training Program Initial Security
Awareness Training: Continuing Security
Awareness Training: Midlevel Management
Security Training: Senior Executive
Management Security Training: |