Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: Security Awareness - Best Ways

Subject: Re: Security Awareness - Best Ways
Date: Thu, 24 May 2007 10:08:48 +0100
When I worked at a particular Investment Bank, even though I was
working for an external consultancy, we had view various interactive
videos on subjects ranging from insider-trading, Anti-Money Laundering
and KYC (Know Your Customer) etc.
This was mandatory for all bank staff/consultants etc.
Since it was also interactive with Q&A, the bank could keep tabs on
those people that had gone through the training and how well they had
done.
Those training videos were rarely longer than 10-15mins, so they
weren't invasive either.
Nor were they taxing on the brain.
You need to bare in mind that most people that will work for your
company are unlikely to be techies. Thus your training needs to be
geared toward such people. Also, you shouldn't take too much for
granted, but don't dumb the classes down, too much, either.

It all depends upon the nature of your business, your data assets,
their value etc.

I'd personally start with basic/general issues. i.e. Laptop Theft =
Loss of corporate asset + company/customer private data (if you're in
the EU, you'll also need to notify the [I think] Data Commissioner
about the data loss), public embarrassment for the company etc...
Make the course topical with examples from the news:
http://www.theregister.co.uk/2007/05/09/printing_security_flap/
http://www.theregister.co.uk/2007/03/28/hospital_laptop_theft/
http://www.theregister.co.uk/2007/02/14/nationawide_fined/
At the end of the lesson, you can point them to the Laptop Usage
policy (which should be a short and simple document that can link to
further documents)
Similar courses relating to Email Policy, Internet Usage, Data Privacy etc.

Thanks,
ys

--
Yousef Syed
"To ask a question is to show ignorance; not to ask a question, means
you remain ignorant" - Japanese Proverb

<Prev in Thread] Current Thread [Next in Thread>