TechKnowSurge
NIST 800-53 AT-2 NIST 800-53 AT-1 CompTIA Security+ 5.6 ISC2 CISSP 1.12 NIST CSF GV.PO-01 NIST 800-53 PL-4 CompTIA Security+ 5.1 ISC2 CISSP 1.8
VideoSecurityFree

Security Awareness & Training Management

Employees represent one of the greatest cybersecurity risks to any organization, making security awareness and training a critical component of any effective cybersecurity program. This content covers the policies, training methods, and testing strategies organizations can use to reduce human-based cyber threats.

Complete this video to capture a CTF flag worth 1 point.

About this video

Employees represent one of the most significant cybersecurity risks within any organization, and cyber criminals routinely exploit human behavior through manipulation and social engineering tactics to gain unauthorized access to infrastructure. Combating this requires a deliberate and multi-layered security awareness and training program that goes beyond occasional reminders and becomes embedded in organizational culture. Foundational to this effort are formal policies, including an acceptable use policy and a dedicated password policy, both of which employees should be required to review and sign to reinforce their importance. Security guidelines integrated into the employee handbook ensure that new hires are introduced to expectations from the moment they are onboarded. Ongoing communication plays an equally important role, with periodic emails or instant messaging used to reinforce key security principles whenever emerging issues or trends warrant attention. Formal training should occur at least annually, though quarterly or continuous programs provide stronger protection and keep security top of mind throughout the year. Testing is a critical and often underutilized element of any awareness program, with phishing simulations being one of the most effective methods for measuring real-world employee behavior. Without regular testing and follow-up, even well-trained employees tend to revert to unsafe habits, making assessment and remediation an essential part of a complete cybersecurity awareness strategy.

What you'll learn

What's covered

Security Awareness & Training

Aligned to

NIST 800-53
AT-2 Literacy Training and Awareness
AT-1 Policy and Procedures
PL-4 Rules of Behavior
CompTIA Security+
5.6 Given a scenario, implement security awareness practices.
5.1 Summarize elements of effective security governance.
ISC2 CISSP
1.12 Establish and maintain a security awareness, education, and training program
1.8 Contribute to and enforce personnel security policies and procedures
NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Acceptable Use Policy
AUP
A documented policy that defines the rules and expectations for how employees and internal users may use organizational systems and resources. An AUP establishes the grounds for disciplinary or legal action if violated.
Password Policy
A set of organizational rules governing the creation, complexity, expiration, and management of user passwords to reduce security risk.
Security Awareness Training
An ongoing program that educates employees about cybersecurity threats, safe practices, and organizational policies to reduce human-based risk. Effective training covers topics like phishing recognition, password hygiene, and social engineering.

Topics

Security Awareness Phishing Simulation Acceptable Use Policy Password Policy Human Factors Cybersecurity

Transcript

The biggest risk to an organization is its employees. Cyber criminals know how to leverage employees and manipulate employees to gain access into an infrastructure, and one of the ways that we can combat this is through awareness and training.

Policies and the employee handbook

A cyber security program needs to have some awareness and training. Some ways that we can convey information, create awareness and train our employees are through the policies that we have, and making employees sign those policies.

We will want to have an acceptable use policy and make our employees sign those acceptable use policies. I like to have a separate password policy to drive home the point, because passwords are so important.

Then there is also the handbook side of this. Inside the employee handbook we could put information regarding our policies and awareness and training, so that way, when employees are onboarded, they will see that information inside the employee handbook.

I also like to send out emails periodically. When I see some issues, or think that something needs to be reiterated, I will send out emails or do messaging within instant messaging.

Training and testing

Then there is this training component. We need to have training at least annually, maybe quarterly, maybe perhaps it is throughout the year, but we need some sort of training to make people aware of cyber security principles.

And then also doing testing, things like phishing campaigns, where we send out test phishing messages to see who responds to that. There is a lot of software that can help us out with that. What I have found is that without that testing that happens afterwards, people are going to continually fail at putting in proper cyber security principles.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →