Automated controls alone cannot prevent or detect security incidents. Knowledge, experience, and awareness on the part of employees play a key role in mitigating information security risk. Security awareness programs are a very important element in IT risk management.
Employees should be educated on various aspects of security events to minimize the impact. Security awareness programs should include do's and don'ts regarding password frameworks, email usage, internet usage, social engineering, and other relevant factors.
Participants
Security awareness training should be provided to all employees irrespective of their job functions or designations and authority. All employees within the organization should be aware of security requirements.
For those job functions where critical data is processed or critical assets handled, enhanced levels of training should be provided. Functions such as OS configuration, programmers, network engineers...