12. Personnel Security 12.1. Information Security Awareness and Training Objective: Mandatory Control 1: Mandatory Control 2: Mandatory Control 3: Recommended Control 1: A security culture is fostered through induction training and ongoing security education tailored to roles, responsibilities, changing threat environment and sensitivity of information, systems and operations Agency management must ensure that all personnel who have access to a system have sufficient information security awareness and training Agencies must provide ongoing information security awareness and training for personnel on topics such as responsibilities, legislation and regulation, consequences of non‐compliance with information security policies and procedures, and potential security risks and counter‐measures, including information on: any legislative or regulatory mandates and requirements any national or agency policy mandates and requirements agency security appointments and contacts the legitimate use of system accounts and software the security of accounts, including shared passwords authorisation requirements for applications, databases and data the security risks associated with non‐agency systems, particularly the Internet reporting any suspected compromises or anomalies reporting requirements for information security incidents, suspected compromises or anomalies protecting workstations from unauthorised access informing the support section when access to a system is no longer needed observing rules and regulations governing the secure operation and authorised use of systems supporting documentation such as SOPs and user guides Agencies must provide information security awareness training as part of their employee induction programmes Agencies should ensure that information security awareness and training includes advice to system users not to attempt to: tamper with the system bypass, strain or test information security mechanisms 51

Select target paragraph3