Objective: A security culture is fostered through induction training and ongoing security education tailored to roles, responsibilities, changing threat environment and sensitivity of information, systems and operations introduce or use unauthorized IT equipment or software on a system replace items such as keyboards, pointing devices and other peripherals with personal equipment assume the roles and privileges of others relocate equipment without proper authorization Agency management is responsible for ensuring that an appropriate information security awareness and training program is provided to personnel. Without management support, security personnel might not have sufficient resources to facilitate awareness and training for other personnel. Awareness and knowledge degrades over time without ongoing refresher training and updates. Providing ongoing information security awareness and training will assist in keeping personnel aware of issues and their responsibilities. Methods that can be used to continually promote awareness include logon banners, system access forms and departmental bulletins and memoranda. Information security awareness and training programs are designed to help system users: become familiar with their roles and responsibilities understand any legislative or regulatory mandates and requirements understand any national or agency policy mandates and requirements understand and support security requirements assist in maintaining security learn how to fulfil their security responsibilities As part of the guidance provided to system users, there should be sufficient emphasis placed on the activities that are not allowed on systems. The minimum list of content will also ensure that personnel are sufficiently exposed to issues that could cause an information security incident through lack of awareness or through lack of knowledge. 52

Select target paragraph3