Category:
Information Technology
Authorizing Body:
Vice President for Administration & Business Affairs – VP-ABA
Responsible Department:
Information Technology Services
Applies To:
Introduction/Purpose
To keep SVSU’s information assets secure and available, security awareness training is administered for new hires and ongoing thereafter to all employees of the organization.
Policy
Acceptance of Security Related Policies
SVSU identifies, develops, and maintains a set of security related policies. These policies are provided to faculty, staff, and each new employee.
Annual Review and Update of Security Related Policies
SVSU keeps all security-related policies updated. At least annually, an Information Technology Services (ITS) leader or individuals assigned by ITS leadership review all security related policies. If updates are recommended, the Executive Director of Information Technology Services approves updates to these policies. SVSU will communicate updates to its employees.
AT 02 - Security Awareness Training
The Information Systems Security Manager and the Executive Director of ITS develop a Security Awareness Training Plan. This plan outlines which training content needs to be delivered to which employee (group).
According to the training plan, employees are trained in security related issues.
AT 03 - Role-based Training
SVSU provides role-based security training to personnel with assigned security roles and responsibilities. This training is based on the training outlined in AT 02 Security Awareness training and provides further instructions necessary for the specific role.
On an annual basis, SVSU reviews the need for role-based training and develop a training program to address these needs:
Role-based training can be accomplished in various ways:
ITS leadership establishes an annual training and qualification program for individuals where role-based training is beneficial. The training is administered over the calendar year. Participation is tracked and training activities are recorded.
AT 04 - Security Training Records
Appendix:
NIST 800.53 - Security and Privacy Controls for Information Systems and Organizations