Awareness and education
End users are one of the most important elements for consideration in the overall security strategy. Training, education, and awareness are of extreme importance to ensure that policies, standards, and procedures are appropriately followed.
Increasing the effectiveness of security training
The most effective way to increase the effectiveness of security training is to customize the training to the target audience and to address the systems and procedures applicable to that particular group. For example, system developers need to undergo an enhanced level of training covering aspects of security related to coding, while data entry operators should be trained on the aspects of security related to their functions.
Key aspects from the CISM exam perspective
The following is one of the key aspects of this topic from an exam perspective: