12.
Personnel Security
12.1.
Information Security Awareness and Training
Objective:
Mandatory Control 1:
Mandatory Control 2:
Mandatory Control 3:
Recommended Control 1:
A security culture is fostered through induction training and
ongoing security education tailored to roles, responsibilities,
changing threat environment and sensitivity of information,
systems and operations
Agency management must ensure that all personnel who have
access to a system have sufficient information security awareness
and training
Agencies must provide ongoing information security awareness
and training for personnel on topics such as responsibilities,
legislation and regulation, consequences of non‐compliance with
information security policies and procedures, and potential
security risks and counter‐measures, including information on:
any legislative or regulatory mandates and requirements
any national or agency policy mandates and requirements
agency security appointments and contacts
the legitimate use of system accounts and software
the security of accounts, including shared passwords
authorisation requirements for applications, databases and
data
the security risks associated with non‐agency systems,
particularly the Internet
reporting any suspected compromises or anomalies
reporting requirements for information security incidents,
suspected compromises or anomalies
protecting workstations from unauthorised access
informing the support section when access to a system is
no longer needed
observing rules and regulations governing the secure
operation and authorised use of systems
supporting documentation such as SOPs and user guides
Agencies must provide information security awareness training as
part of their employee induction programmes
Agencies should ensure that information security awareness and
training includes advice to system users not to attempt to:
tamper with the system
bypass, strain or test information security mechanisms
51