|
+ORP.3 Awareness and Training in Information Security ---+ORP.3.G1. Insufficient Knowledge of Rules and Procedures ---+ORP.3.G2. Insufficient Awareness of Information Security ---+ORP.3.G3. Ineffective Awareness and Training Activities ---+ORP.3.G4. Insufficient Employee Training Regarding Security Functions ---+ORP.3.G5. Undetected Security Incidents ---+ORP.3.G6. Non-Compliance with Security Safeguards ---+ORP.3.G7. Carelessness in Handling Information ---+ORP.3.G8. Lack of Acceptance of Information Security Policies ---+ORP.3.G9. Social Engineering ---+ORP.3.A1 Top Management Awareness of Information Security Issues [Supervisor, Top Management] (B) ---+ORP.3.A3 Training Employees in the Secure Handling of IT [Supervisor, Human Resources Department, IT Operation Department] (B) ---+ORP.3.A4 Designing and Planning an Information Security Awareness and Training Program (S) ---+ORP.3.A6 Implementation of Information Security Awareness and Training Measures (S) ---+ORP.3.A7 Training in the IT-Grundschutz Methodology (S) ---+ORP.3.A8 Measurement and Evaluation of Training Success [Human Resources Department] (S) ---+ORP.3.A9 Special Training for Exposed Persons and Organisations (H) |
1. ÜbersichtORP.3 Awareness and Training in Information Security1. Description1.1. Introduction Employees are a crucial factor in ensuring a high level of information security in an organisation. It is therefore important that each and every one of them know their organisation's security objectives, understand the corresponding security safeguards, and be willing to implement them. This requires security awareness within the organisation in question. Furthermore, a culture of security should be established that forms an active part of employees' everyday work. Employees should be made aware of relevant risks and know how they may affect their organisation. They must know what is expected of them in terms of information security and how they should respond in situations critical to security. 1.2. Objective This module describes how to establish and maintain an effective program for raising awareness and conducting training on information security. The aim of the program is to raise employees' awareness of security risks and provide them with the knowledge and skills required to act in a security-conscious manner. 1.3. Scoping and Modelling Module ORP.3 Awareness and Training in Information Security must be applied once to the entire information domain under consideration. This module formulates requirements for information security awareness and training which relate to the working environment not only within an organisation, but in teleworking and mobile working settings, as well. Module ORP.3 Awareness and Training in Information Security describes process-related, technical, methodological, and organisational requirements for information security awareness and training. An organisation's human resources department or training management department typically plans, manages, and implements other training topics, as well. Specific training content for these topics is covered in many of the other IT-Grundschutz modules. This module deals with how a planned approach can be efficiently structured with regard to information security awareness and training. 4. Additional Information 4.1. Useful Resources The International Organization for Standardization (ISO) provides requirements for training employees and raising their awareness in the ISO/IEC 27001:2013 standard, section 7.2. The Information Security Forum (ISF) defines various requirements for training employees and raising their awareness in "The Standard of Good Practice for Information Security", section PM2. The BSI offers an online course on IT-Grundschutz at https://www.bsi.bund.de/grundschutzkurs, which introduces the methodology of IT-Grundschutz. The BSI offers a two-stage training concept on the subject of IT-Grundschutz. In this training concept, participants can acquire an IT-Grundschutz practitioner certificate and be further certified as an IT-Grundschutz consultant by the BSI. A list of training providers that offer BSI training to become an IT-Grundschutz practitioner and an IT-Grundschutz consultant can be found at https://www.bsi.bund.de/DE/Themen/ITGrundschutz/ITGrundschutzSchulung/ITGrundschutzBerater/itgrundschutzberater_node.html.
1.1 Referenzen1.2 Identifizierte Anforderungen1.2 Related Regulation2. Identifizierte Anforderungen
3. Related Regulations
Linked Issues |