AWARENESS AND TRAINING
27.1 Objective
The objective of this Policy is to educate and train users effectively and efficiently using applications and technology solutions to ensure user compliance with policies and procedures.
27.2 Policy
a) Establish and regularly update a curriculum for each target group of employees considering:
(i) Current and future business needs and strategies
(ii) Value of information as an asset
(iii) Corporate values (ethical values, control and security culture, etc.)
(iv) Implementation of new IT infrastructure and software (i.e., packages, applications)
(v) Current and future skills, competency profiles, and certification and/or credentialing needs as well as required reaccreditation
(vi) Delivery methods (e.g., classroom, web-based), target group size, accessibility and timing
b) Based on the identified education and training needs, identify target groups and their members, efficient delivery mechanisms, teachers, trainers, and mentors. Appoint trainers and organise timely training sessions. Record registration (including prerequisites), attendance and training session performance evaluations.
c) Evaluate training education and provided training upon completion for relevance, quality, effectiveness, retention of knowledge, cost measurements and overall value. The results of this evaluation should serve as an input for future curriculum definition and enhanced training sessions.
d) Staff must be made aware of and trained to maintain strict confidentiality with regards to all information obtained in the course of their work and should never misuse any privileged information. It must ensure that all staff complies with applicable laws, regulations and guidelines and any deliberate violation should be subjected to disciplinary action.