Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Call Center Folks Have Huge Amounts Of Access TO PII | Main | Death and Data »

People Need Periodic, Effective, Training And Ongoing Awareness To Truly Safeguard Information

Imagine this; what if you were given training just one time, in a 1-hour session with no hands-on practice, for how to do first aid and give CPR and then were never given more training or reminders about how to do first aid and CPR...two years later would you be able to competently perform first aid when someone needed it? Probably not. Probably not even 1 year later, or even 6 months later.

People need to have regularly scheduled training and ongoing awareness in how to do activities competently. You cannot expect to give a 1-hour, often poorly-constructed, training course about information security or privacy and the have the people taking the training know what to do weeks or months or even yeas later. However, this is the situation that occurs in a very large portion of organizations.

It is no wonder that the majority of security incidents and privacy breaches occur as a result of lack of knowledge and mistakes.

Here is the third part of the third article, "Providing Call Centers with Information Security and Privacy Education," in my July issue of IT Compliance in Realtime, that speaks to this issue...

-----------------------------------

Make Awareness Ongoing to Make Security Effective

An effective information security and privacy awareness program must communicate to personnel, outside of the formal training sessions, the importance of observing and maintaining information security and privacy as well as motivate personnel to learn and follow the organization's information security and privacy policies and procedures. Call center personnel must receive ongoing communications about the situations they deal with every day that involve information security and could result in privacy breaches.

These ongoing communications should occur in a variety of ways to help ensure that all call center staff knows and understands the importance of properly following information security and privacy procedures. Tailor awareness communications and activities to one of the following three types of learners to truly educate all your personnel:

  • Visual--These are the folks who learn best through seeing and reading.
  • Audio--These folks learn best by listening to information.
  • Kinesthetic--These are hands-on learners; those who need to do some type of activities to learn.

Over the years, I have accumulated and documented more than 200 types of information security and privacy awareness communications and activities for businesses to use. Some are available online and others are provided in my book Managing an Information Security and Privacy Awareness and Training Program. Most of these would work quite well for call center personnel.

-----------------------------------

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/772

Comments

It's so true - I have taken the CPR classes before and I'm not sure I remember everything I would need to do if there was ever an emergency. You definitely need to have ongoing refreshers.

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.