2.1.3: Staff training

Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.

Objective: If the requirements and risks of information security are not known to the employees, there is a risk of misconduct resulting in damage to the organization. Therefore, it is important that information security is internalized and practiced as a natural part of their work.

Requirements (must): Employees are trained and made aware.

Requirements (should): A concept for awareness and training of employees is prepared. As a minimum, the following aspects are considered:
- Information security policy,
- Reports of information security events,
- Reaction to occurrence of malware,
- Policies regarding user accounts and login information (e.g. password policy),
- Compliance issues of information security,
- Requirements and procedures regarding the use of non-disclosure agreements when sharing information requiring protection,
- Use of external IT services.
Target groups for training and awareness measures (i.e., people working in specific risk environments such as administrators, employees having access to customer networks, personnel in areas of manufacturing) are identified and considered in a training concept.
The concept has been approved by the responsible management.
Training and awareness measures are carried out both at regular intervals and in response to events.
Participation in training and awareness measures is documented.
Contact persons for information security are known to employees.

This requirement is part of the framework:  
TISAX: Information security
Best practices
How to implement:
2.1.3: Staff training

Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.

Objective: If the requirements and risks of information security are not known to the employees, there is a risk of misconduct resulting in damage to the organization. Therefore, it is important that information security is internalized and practiced as a natural part of their work.

Requirements (must): Employees are trained and made aware.

Requirements (should): A concept for awareness and training of employees is prepared. As a minimum, the following aspects are considered:
- Information security policy,
- Reports of information security events,
- Reaction to occurrence of malware,
- Policies regarding user accounts and login information (e.g. password policy),
- Compliance issues of information security,
- Requirements and procedures regarding the use of non-disclosure agreements when sharing information requiring protection,
- Use of external IT services.
Target groups for training and awareness measures (i.e., people working in specific risk environments such as administrators, employees having access to customer networks, personnel in areas of manufacturing) are identified and considered in a training concept.
The concept has been approved by the responsible management.
Training and awareness measures are carried out both at regular intervals and in response to events.
Participation in training and awareness measures is documented.
Contact persons for information security are known to employees.

Read below what concrete actions you can take to improve this ->
Frameworks that include requirements for this topic:
No items found.

How to improve security around this topic

In Cyberday, requirements and controls are mapped to universal tasks. A set of tasks in the same topic create a Policy, such as this one.

Here's a list of tasks that help you improve your information and cyber security related to
2.1.3: Staff training
Task name
Priority
Task completes
Complete these tasks to increase your compliance in this policy.
Critical
No other tasks found.

How to comply with this requirement

In Cyberday, requirements and controls are mapped to universal tasks. Each requirement is fulfilled with one or multiple tasks.

Here's a list of tasks that help you comply with the requirement
2.1.3: Staff training
of the framework  
TISAX: Information security
Task name
Priority
Task completes
Complete these tasks to increase your compliance in this policy.
Critical
Ensuring coverage of relevant topics on personnel training and guidance processes
Critical
High
Normal
Low
2
requirements
Personnel security
Cyber security training

Ensuring coverage of relevant topics on personnel training and guidance processes

This task helps you comply with the following requirements

Amount, competence and adequacy of key cyber security personnel
Critical
High
Normal
Low
23
requirements
Risk management and leadership
Cyber security management

Amount, competence and adequacy of key cyber security personnel

This task helps you comply with the following requirements

General security competence and awareness of personnel
Critical
High
Normal
Low
25
requirements
Risk management and leadership
Cyber security management

General security competence and awareness of personnel

This task helps you comply with the following requirements

Arranging training and guidance during orientation (or before granting access rights)
Critical
High
Normal
Low
Informing staff about new, relevant malware
Critical
High
Normal
Low

The ISMS component hierachy

When building an ISMS, it's important to understand the different levels of information hierarchy. Here's how Cyberday is structured.

Framework

Sets the overall compliance standard or regulation your organization needs to follow.

Requirements

Break down the framework into specific obligations that must be met.

Tasks

Concrete actions and activities your team carries out to satisfy each requirement.

Policies

Documented rules and practices that are created and maintained as a result of completing tasks.

Never duplicate effort. Do it once - improve compliance across frameworks.

Reach multi-framework compliance in the simplest possible way
Security frameworks tend to share the same core requirements - like risk management, backup, malware, personnel awareness or access management.
Cyberday maps all frameworks’ requirements into shared tasks - one single plan that improves all frameworks’ compliance.
Do it once - we automatically apply it to all current and future frameworks.