UNCLASSIFIED
4.5
Awareness, Education and Training
The purpose of awareness, education and training is to foster an organisational
culture that values, protects and handles information assets safely and thereby
achieves the mandatory minimum-security outcomes outlined below.
GV4 – Organisations must ensure that all users – including Ministers, Board
members, senior executives, employees and third party users – obtain
security awareness before gaining access to critical infrastructure. As a
minimum requirement, the awareness must: (a) as part of the induction
process, explain to staff the security risks associated with their work; (b) help
staff gain awareness of the organisation’s security policies; (c) remind staff of
their personal responsibility for safeguarding assets entrusted to them; (d)
articulate potential penalties for breaching security rules; (e) be assessed
formally; and; (f) be repeated at least annually.
To achieve the security outcomes mandated above, organisations must:
4.6
Conduct security induction training for all employees, including contractors
and subcontractors, to ensure that they are conversant with organisational
security policies and procedures as well their personal accountability for
securing assets under their control and/or supervision;
Allocate sufficient resources to finance a sustained user security awareness
and education programme covering relevant risks, threats and vulnerabilities;
acceptable usage; impacts of cyber attacks; incident response actions and
the personal consequences of breaching security rules;
Avail security policies to all staff, including contractors, internally;
Ensure that all staff, including contractors, obtain appropriate briefings about
how legislation identified in this policy, in particular, the Official Secrets, the
Access to Information, the Computer Misuse, the Electronic Signatures and
the Electronic Transactions Acts affect their work activities;
Provide security cleared staff training matching their access privileges;
Ensure that staff performing security roles receive suitable training; and
Regularly review and re-evaluate the effectiveness of security awareness
and education activities in light of a changing threat environment.
Business Continuity & Disaster Recovery
Business continuity activities aim to show that the organisation has the capacity
to withstand interruptions to critical business activities and thereby achieve the
mandatory minimum-security outcomes outlined below.
17