Reviewing Security Awareness Security awareness is a state of consciousness in which individuals or groups are cognizant of security issues and what they need to do to mitigate threats. A different level of security awareness can be defined for different groups of people. That is, the ordinary computer user needs to know and practice different information security than the IT administrator. The user needs to have specific knowledge that will allow her to securely operate and use computer systems and manage sensitive information, including any information that might be used to compromise the organization's computer systems. The IT administrator, because she has more knowledge and more privileges on computer systems, needs to have the end user's knowledge plus much, much more. Other individuals within the organizations may also have different security awareness needs.All members of the organization can benefit from security awareness training that is directed toward their needs. An audit of security awareness should judge the status of knowledge, review the security awareness program, and test the program both by observation (are passwords written on sticky notes and attached to computer monitors?) and by active attempts at social engineering (perhaps a phone call that attempts to obtain a password). |