문서의 이전 판입니다!

인식제고 관리

정보보안 인식(Security awareness)

(출처 : wikipedia)
보안 인식은 물리적이고 특별한 조직의 특별한 정보자산의 보호에 관련하여 조직 구성원의 지식과 태도를 말한다.

정보인식 훈련에 포함할 내용 :

  • The nature of sensitive material and physical assets they may come in contact with, such as trade secrets, privacy concerns and government classified information
  • Employee and contractor responsibilities in handling sensitive information, including review of employee nondisclosure agreements
  • Requirements for proper handling of sensitive material in physical form, including marking, transmission, storage and destruction
  • Proper methods for protecting sensitive information on computer systems, including password policy and use of two-factor authentication
  • Other computer security concerns, including malware, phishing, social engineering, etc.
  • Workplace security, including building access, wearing of security badges, reporting of incidents, forbidden articles, etc.
  • Consequences of failure to properly protect information, including potential loss of employment, economic consequences to the firm, damage to individuals whose private records are divulged, and possible civil and criminal penalties

Security awareness training is a formal process for educating employees about computer security.

A good security awareness program should educate employees about corporate policies and procedures for working with information technology (IT). Employees should receive information about who to contact if they discover a security threat and how to handle confidential information. Regular training is particularly necessary in organizations with high turnover rates and those that rely heavily on contract or temporary staff. Confirming how well the awareness program is working can be difficult. The most common metric looks for a downward trend in the number of incidents over time.

The National Institute of Standards and Technology (NIST) has an excellent publication with templates and guides for what should go into a security awareness training program. The 70-page document is available for free in PDF format from the institute's Web site.