Awareness and Education
End users are one of the most important stakeholders when considering the overall security strategy. Training, education, and awareness are of extreme importance to ensure that policies, standards, and procedures are appropriately followed.
Increasing the Effectiveness of Security Training
The most effective way to increase the effectiveness of training is to customize it as per the target audience and to address the systems and procedures applicable to that particular group. For example, a system developer needs to undergo an enhanced level of training that covers secure coding aspects. By contrast, data entry operators only need to be trained on security aspects related to their functions.
Key Aspects from the CISM Exam Perspective
Following are some of the key aspects from the perspective of the CISM exam:
Question |
...