User Education

As a minimum, a Local Authority's Information Security Policy should include:

  • A definition of Information Security
  • A statement of management intent
  • a brief explanation of security policies, principles, standards and compliance requirements of particular importance to the organisation
  • A definition of General and specific security responsibilities
  • References to supporting documents

A sample "personal commitment statement" is included in the Code of Connection Guidance notes.

ISO27001 provides comprehensive detail on policy areas that may need to be included:

  • Security policy
  • Organising information security
  • Asset management
  • Human Resources security
  • Physical and environmental security
  • Communications and operations management
  • Access control
  • Information systems acquisition, development and maintenance
  • Information security incident management
  • Business continuity management
  • Compliance

 


Suggested Solutions

Amberhawk provide training courses on Data Protection, FoI, RIPA, Information Security Law and Information Law compliance. Courses are run throught the year at various locations, or can be run on site.

More information can be obtained at http://www.amberhawk.com/ or by emailing info@amberhawk.com

 

Encription limited can offer focused, interactive security awareness training for your staff, either in-house or online. Modules include:

Information Security Basics, Access Control, Appropriate and Personal Use, Mobile Computing, Intrusions and Malicious Software, Email Security, Internet Security,Information Management and Data, Incident Handling and Reporting, Remote Access and Physical Security

To see what Tiger Certified Encription Limited can do on IT Security training give us a call 01905 754440 or go to http://encription.co.uk/training.php

 

IBM Culture Transformation Practice can help you design the necessary strategy and interventions.

More information can be found here

 

Safend Data Protection Suite provides security administrators with the tools for ensuring end user involvement in the data protection process. When a policy violation is detected, a customisable message is displayed to the end user. This is a highly effective method of deterring users from committing harmful actions, without disrupting legitimate business procedures. Read More

 

Sapphire’s consultancy team is well respected as experts in designing a range of tailored awareness and training exercises, user publications and tailor made workshops (including forensic training / internal audit) to achieve the required information security culture. These training sessions are often presented as part of a larger consultancy project. For further information please email Coco Information or call 01642 702100.