Incorporating data-breach issues in employee training - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Security

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

Hacker writes Cisco rootkit; Microsoft launches online telescope. Listen now!

Network World 360

Wireless dangers at airports. Listen now!

Network World Panorama

Additional Resources

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Reduce Complexity and Cost - Windows Server Consolidation with Virtualization from Novell Novell

There are many compelling reasons for virtualizing Windows and Linux applications. Virtualization improves server utilization by allowing you to run multiple workloads on a single physical server. It reduces the number of physical servers you have to maintain, while allowing you to use less physical space and power while still improving scalability. All of these capabilities translate directly into lower costs, less complexity, and greater flexibility in your mixed IT environment. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

The 3G Punch? There have been good 3G phones out for months and months and years.- Anonymous

Join the Discussion

Incorporating data-breach issues in employee training

Insider Threat By Jerry Ervin , Network World , 07/09/2007
  • Social Web 
  • Email 
  • Feedback 
  • Close

I manage an employee training program and wondered how often we should have refresher courses on company policy about data protection and confidential company information. What are your recommendations?

In developing any program we first have to look at the needs gap. What are the requirements of our corporate policy about data protection and confidential company information, and what are the skills our team needs to understand to adhere to that policy?

As training managers, we are charged with creating orientation training  for new employees as well as skill and behavior training modules. During the orientation is when most of the corporate policy and procedures are first presented. Yet our staff needs to be reminded from time to time about the importance of this very sensitive issue. Carolyn Balling, professional development manager, Northern California Human Resources Association, said, "Is this really a job for the training department or is it a job for the internal communications department, and second, would our team members even attend the training?"

Our staff is increasingly busy with their work. Their most valuable asset is their time. When it comes to training, they have to weigh the value of this program against their daily duties and responsibilities. Usually skill and behavior training is a priority over policy training. Lee Stapleton, training manager at Organic, Inc., said "It's hard enough to fill even our skill-based programs. Our team would be challenged to attend a policy and procedure training with their busy schedules. They would not see the value to themselves personally."

When we think about what we are really trying to do, mainly it is to remind our team of the importance of protecting data and confidential information. Our staff does understand the concept; their mistakes mostly arise from errors in judgment.

My recommendation would be to work with your internal communications department and create a company-wide initiative. The immediate step is to enroll the management team. This could include a short management meeting, similar to a train-the-trainer program, that highlights the challenges of protecting data and confidential information, the cost impact of data breaches, and case studies on the importance of protection. From there, training can be supported and delivered to the whole company through the internal newsletter and/or an e-mail blast. I would suggest conducting an annual audit to determine the necessity of this program.

1 | 2 |  Next >
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code