SETA Programs
It is often said that cybersecurity is made up of three things – people, processes, and technology. Of those three things, the people aspect is the weakest link. You can have all the policies, processes, and technology but if your people are working against you, then you have no chance. This section will talk about SETA programs, their importance, methods and techniques, and how to gauge their effectiveness. The objective is to create an educated workforce that is less vulnerable to cybersecurity attacks. One of the first things to understand about SETA is the most effective order of its implementation, which is Awareness, then Training, and finally, Education.
As NIST SP800-16 says “Awareness is not training. The purpose of awareness presentations is simply to focus attention on security. Awareness presentations are intended to allow individuals to recognize IT security concerns and respond accordingly.” Awareness is the crucial first step in...