Security training and awareness
In both John's and Joyce's cases, the theme of security awareness may be focused on PCI DSS compliance. There are many ways to deliver security training, such as posters, newsletters, e-learning or teleconferencing, in-person workshops, or hands-on tutorials. NIST SP 800-50 Building an Information Technology Security Awareness and Training Program and PCI DSS Best Practices for implementing a Security Awareness Program are two good references for building a security awareness program. Here, we discuss some of the key points to consider when delivering a security awareness and training program with an organization.
Sending newsletters is considered to be one of the most cost-effective and common practices to target all employees across business units. What can be even more effective is to look at a real example or case study that relates to that role or the business. For example, HR may be more interested in stories or case studies about employment related...