Awareness Flashcards

(3 cards)

1
Q

Awareness

A

A cybersecurity awareness program is an initiative to educate people on cybersecurity topics and make them aware of organizational policy and their responsibilities regarding the IT and OT resources entrusted to them.

NIST 800-50 covers IT Information security awareness.

IEC62443 recommends cybersecurity in IACS should be equally emphasized as safety.

Cybersecurity awareness programs are therefore applicable to all persons.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Effectiveness of Awareness

A

Cybersecurity awareness programs are only effective if they are tailored to the audience, consistent with company policy, and regularly communicated.

Depending on the type of audience, the awareness activities should be tailored so that the audience can relate to the context and applicable policies.

The awareness activities need to be repeated in a fashion that keeps drawing the intended audience’s attention and changes their behavior in the desired direction.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Examples of Awareness Program

A

1- E-learning content for all IT-OT staff with assessment at the end.
2 - Red team/Blue team exercises by simulating the IACS environment.
3 - Showcasing the impact of malware infestation through simulation.
4 - Conducting Incident response drills.
5 - Board member’s session on high-impact IACS cybersecurity risks and how they affect the business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly