错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Exploring Cybersecurity Training and Awareness Approaches

  • Reismary Armas,
  • Hamed Taherdoost

摘要

Information security frameworks are essential for organizations to establish comprehensive approaches to safeguarding their information. Offering guidelines, best practices, and standards not only to protect data and systems but also to support and recommend setting awareness and training programs for organizations in general. The objective of these frameworks is not only to provide the basis for security policies and procedures and the development of security awareness and training initiatives, but also emphasize the assessment of human-managed risks. This, in turn, educates employees and other interested parties about the importance and benefits of information security and the implications of not managing or complying with these matters. This document analyzes the key frameworks’ contribution to cybersecurity awareness and training, such as the National Institute of Standards and Technology (NIST), ISO/IEC 27,001 and 27,002, the SANS security awareness maturity model, and the Center for Internet Security Controls (CIS), in its latest version CIS Controls v8, and COBIT 2019. It ends with a conclusion about the points of improvement that exist in each framework and how these could be complemented.