Training general users on the non-policy side of the IS program
Hamza Amor · 2010
Once an information security program is put in place in an organization, the program needs to be managed and formal training needs to take place in order to get everyone to comply with the policies resulting from the program. Most of the training and education is conducted on these policies, but there is also a need to train users on some general good security practices, password management practices, access control management, and violation reporting that may not be part of the policies laid out by the information security program. This paper will focus on this aspect of the information security program training.