Security in job definition and resourcing:
The objective of this control is to reduce the risks of human error, theft, fraud or misuse of facilities.
User training:
The objective is to ensure that users are aware of information security threats and concerns, and are equipped to support organisational policy in the course of their normal work.
Responding to security incidents and malfunctions:
The objective of this control is to minimize the damage from security incidents and malfunctions, and to monitor and learn from such incidents