UNCLASSIFIED 4.5 Awareness, Education and Training The purpose of awareness, education and training is to foster an organisational culture that values, protects and handles information assets safely and thereby achieves the mandatory minimum-security outcomes outlined below. GV4 – Organisations must ensure that all users – including Ministers, Board members, senior executives, employees and third party users – obtain security awareness before gaining access to critical infrastructure. As a minimum requirement, the awareness must: (a) as part of the induction process, explain to staff the security risks associated with their work; (b) help staff gain awareness of the organisation’s security policies; (c) remind staff of their personal responsibility for safeguarding assets entrusted to them; (d) articulate potential penalties for breaching security rules; (e) be assessed formally; and; (f) be repeated at least annually. To achieve the security outcomes mandated above, organisations must: 4.6  Conduct security induction training for all employees, including contractors and subcontractors, to ensure that they are conversant with organisational security policies and procedures as well their personal accountability for securing assets under their control and/or supervision;  Allocate sufficient resources to finance a sustained user security awareness and education programme covering relevant risks, threats and vulnerabilities; acceptable usage; impacts of cyber attacks; incident response actions and the personal consequences of breaching security rules;  Avail security policies to all staff, including contractors, internally;  Ensure that all staff, including contractors, obtain appropriate briefings about how legislation identified in this policy, in particular, the Official Secrets, the Access to Information, the Computer Misuse, the Electronic Signatures and the Electronic Transactions Acts affect their work activities;  Provide security cleared staff training matching their access privileges;  Ensure that staff performing security roles receive suitable training; and  Regularly review and re-evaluate the effectiveness of security awareness and education activities in light of a changing threat environment. Business Continuity & Disaster Recovery Business continuity activities aim to show that the organisation has the capacity to withstand interruptions to critical business activities and thereby achieve the mandatory minimum-security outcomes outlined below. 17

Select target paragraph3