Ch 17: Human Resources Security

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/23

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:47 PM on 4/23/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

24 Terms

1
New cards

Security awareness, training, and education programs provide four major benefits to organizations:

  • improving employee behavior

  • increasing the ability to hold employees accountable for their actions

  • Mitigating liability of the organizations for an employee’s behavior

  • complying with regulations and contractual obligations

2
New cards

______ behavior is a critical concern in ensuring the security of computer systems and info assets.

Employee

3
New cards

What are the principal problems associated with employee behavior?

  • social engineering and phishing attacks

  • compromised/weak credentials

  • errors and omissions

  • fraud and actions by disgruntled employees

4
New cards

Security awareness, training, and education programs can assist in reducing incidences by increasing employees’ knowledge of their ______.

accountability

5
New cards

Ongoing security awareness, training, and education programs are also important in limiting an organization’s ________.

liability

6
New cards

Security awareness, training, and education programs may be needed to comply with…

regulations & contractual obligations

7
New cards

There is a need for a continuum of learning programs that starts with ____, builds to ____, and evolves into ____.

awareness, training, education

8
New cards

What are the four layers of the Learning Continuum?

  • security awareness

  • cybersecurity basics & literacy

  • role-based security training

  • security education & certification

9
New cards

security awareness

set of activities that explains & promotes security, established accountability, and informs the workforce of security news

10
New cards

cybersecurity basics & literacy

develop secure practices in the use of IT sources

11
New cards

role-based security training

provides knowledge & skills specific to an individual’s roles & responsibilities relative to information systems

12
New cards

security education & certification

integrates all security skills & competences of various functional specialties into a common body of knowledge

13
New cards

A successful IT security training program consists of:

  1. developing IT security policy that reflects business needs given known risks

  2. informing users of their IT security responsibilities

  3. establishing processes for monitoring & reviewing the program

14
New cards

T/F: Although all employees have security responsibilities, not all employees must have suitable security awareness training.

False; all employees must have

15
New cards

The overall objective of the organization should be to develop a security awareness program that

permeates to all levels of the organization and is successful in promoting an effective security culture

16
New cards

What are specific goals for a security awareness program?

  • providing a focal point and a driving force for a range of awareness, training, and educational activities related to information security

  • communicating important recommended guidelines or practices

  • providing general & specific info abt inforation security risks & controls

  • motivating individuals to adopt recommended guidelines / practices

  • being driven by risk considerations

  • Providing employees with an understanding of the different types of inappropriate behavior and how to avoid

  • creating a stronger culture of security

  • helping enhance the consistency & effectiveness of existing info security controls and stimulating adoption of cost-effective controls

  • help minimize the # and extent of breaches, reducing costs

17
New cards

What are the two options for the awareness program designer?

  • use in-house materials

  • use externally obtained materials

18
New cards

T/F: A well designed awareness training program might have materials from only one source

False; both sources

19
New cards

What are effective in-house materials?

  • brochures, leaflets, fact sheets

  • security handbook

  • regular e-mail or newsletter

  • distance learning

  • workshop & training sessions

  • formal classes

  • video

  • website

20
New cards
21
New cards
22
New cards
23
New cards
24
New cards