Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: IT Security Awareness program |
|---|---|
| Date: | Wed, 26 Jul 2006 18:11:26 +0200 |
Dear Dashti,
There are some special trainings where you can learn more about how to build an efficient information security awareness within your organisation, but these are some basic tips:
- try to align the awareness program to your company information security policies,
- adjust the training to the specific incidents or risks that are most common to your organisation,
- use graphs, statistics, films, posters, banners etc - try to make a dynamic but also an ongoing process,
- do not forget to measure the efficiency of the whole program,
- I would personally start from the top management.
Try different consultants and awareness vendors, for sure they can help you with some ideas. My friends at infosecuritylab used to offer three months free awareness training - so you can train your staff for free by a computer supported environment and see, if this is applicable for you. Sometimes it is easier to do face-to-face training. Also I would recommend you to see the video that was prepared and shows the entire process: http://www.infosecuritylab.com/downloads/walkthrough/walkthrough.wmv.
One of my students recently managed to get all the information from a bank account in less then 6 hours spent on the phone, by using specific topics of social engineering. It is a long story, but you would not believe, how simple it can be. Bank employees are specially vulnerable to those attacks, therefore try to do some awareness in the most simple areas of information security.
Be secure,
A.
P.S.: Try to measure whatever you do, so you can improve the process in the future!
Dear all ...
Can someone help me on how to build good IT Security Awareness
program ..
Thanx
May A Dashti
IT Security Officer
Risk Management
Kuwait Real Estate Bank
Tel. (965) 888 999 - Ext. 3144
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Meeting Security Compliance Policies, mattdavis |
|---|---|
| Previous by Thread: | RE: IT Security Awareness program, robin.skitt |
| Next by Thread: | Financial Institution Shared Assessments Program (FISAP), lists@infostruct.net |
| Indexes: | [Date] [Thread] [Top] [All Lists] |