Managing an Information Security and Privacy Awareness and Training Program provides a starting point and an all-in-one resource for infosec and privacy education practitioners who are building programs for their organizations. The author applies knowledge obtained through her work in education, creating a comprehensive resource of nearly everything involved with managing an infosec and privacy training course. This book includes examples and tools from a wide range of businesses, enabling readers to select effective components that will be beneficial to their enterprises. The text progresses from the inception of an education program through development, implementation, delivery, and evaluation.
"Rebecca Herold has the answers in her definitive book on everything everybody needs to know about how to impart security awareness, training, and motivation. Motivation had been missing from the information security lexicon until Herold put it there in most thorough and effective ways She demonstrates that security must become a part of job performance rather than being in conflict with job performance "The power of this book also lies in applying real education theory, methods, and practice to teaching security awareness and training After reading this book, there is no question about the necessary and important roles of security awareness, training, and motivation." Donn B. Parker, CISSP, from the Preface
"This book is remarkable because it covers in detail all the facets of providing effective security awareness training I can, without reservation, recommend use of this book to any organization faced with the need to develop a successful training and awareness program. It surely provides everything you need to know to create a real winner." Hal Tipton, from the Foreword
Features: Provides a starting point and an all-in-one resource for information security and privacy education practitioners Justifies the importance of training and awareness, emphasizing legal and regulatory requirements Contains examples of real education experiences and case studies for information security teaching Includes 142 awareness materials and methods and 42 tips to trainers Directs readers to multiple resources for more specialized information Offers 22 appendices of sample forms, slide presentations, checklists of course content, and other resources that readers can apply to their own education program