An  organization should establish an effective cybersecurity training  program for personnel having authorized access to critical cyber assets.

Create  a training plan for everyone who works at the organization. The  training plan should address (but is not limited to) the following:

  1. Articulate a culture of security awareness, collaboration, and buy-in among management, staff, clients, and stakeholders.
  2. Describe common security risks and how to avoid them.
  3. Describe policies, access controls, and procedures developed for critical electronic devices and communication networks.
  4. Describe the proper use of critical electronic devices and communication networks.
  5. Describe the proper handling of critical information.
  6. Present action plans and procedures to recover or reestablish critical electronic devices and communication networks.
  7. Address the risks resulting from insecure behavior of employees.

