Methods and Techniques to Present Awareness and Training

4 slides · 3 min read · Domain 1

Methods and Techniques to Present Awareness and Training

Cybersecurity awareness and training are best supported through regular sessions, real-world simulations, clear policies, and engaging, role-specific content that highlights threats and safe practices.

  • Regular communications. A one-time

Effective cybersecurity

session, whether it is live training or CBT,

awareness and training can

is a single event. To retain knowledge,

be achieved through various

employees must be continually reminded methods:

about relevant risks and threats. Maintaining regular communication can be in the form of a monthly newsletter

  • Computer-based training (CBT). Online

(often via the internal website or email training enables employees to train at blast) or visible reminders, such as signage, their own pace and on their own schedule.

screensavers, and posters.

It is also highly efficient, allows for standardization of content and delivery,

  • Reward mechanisms. Traditionally, the and usually includes automatic assessment security office was a mechanism for and tracking capabilities. A downside of enforcing the policy, which usually CBT, however, is the common employee resulted in negative consequences for habit of clicking through material without employees. If, instead, the organization absorbing or retaining it to simply uses rewards for demonstration of good complete a task they consider a nuisance. (secure) performance, this can increase CBT is particularly useful when combined the security of the organization by with fake phishing or social engineering fomenting correct behavior and creating attacks that test the employees ability a feeling of goodwill between users and to spot and act correctly when they the security department. Rewards can see the hallmarks of a phishing or social be as basic as written congratulations engineering campaign. This approach can (which can be accented for importance by validate training effectiveness and identify including the letterhead and signature of staff who may require additional training. a senior manager) or as important as cash bonuses or paid vacation.
  • Live, in-person training. Live training requires scheduling a specific meeting time, which can reduce enthusiasm and affect attendance. Live training also requires a subject matter expert who is also a skilled trainer. However, live training counters the possibility of click-through, can elicit and address subject matter questions in real time, and can present an opportunity for the security department to build rapport with the user community. Live training can be particularly effective when combined with team-building exercises and competitions.
  • Online synchronous training. If in-person training is not feasible, training can be conducted using virtual collaboration platforms.
  • Gamification. People love games— introducing gamification into the security awareness program increases both engagement and knowledge retention. OWASP's Cornucopia is a great example of gamification. Playing the game with developers encourages debate within the team on strategies for building defensive code.
  • Security Champions. The development of a formal Security Champion program can extend the reach of security education and awareness efforts using staff from different areas of the organization who volunteer their time to understand security issues more deeply and help apply the principles in their area. Champions can come from any area of the business; they deliver key messages and provide examples of good practice through their day-to-day behavior.
Test this domain