Role-Based Security Training



Similar documents
Enhancing NASA Cyber Security Awareness From the C-Suite to the End-User

Role-Based Security Training Awareness. I am D Andrea Spann Training Specialist assistant to John Whiting for Role- Based Security Training.

IT SECURITY EDUCATION AWARENESS TRAINING POLICY OCIO TABLE OF CONTENTS

Role of Awareness and Training for Successful InfoSec Security Program 1

Enterprise Application Security Practices: Realworld Tips and Techniques

DEPARTMENT OF VETERANS AFFAIRS VA DIRECTIVE 6517 CLOUD COMPUTING SERVICES

Lessons Learned in Security Measurement. Nadya Bartol & Brian Bates Booz Allen Hamilton

UNITED STATES DEPARTMENT OF AGRICULTURE FOOD SAFETY AND INSPECTION SERVICE WASHINGTON, DC INFORMATION SYSTEM CERTIFICATION AND ACCREDITATION (C&A)

Creating a Training Program and Learning Culture in Your Organization

Smart library : Community-based Financial Education. Cynthia Needles Fletcher Iowa State University

5 FAM 620 INFORMATION TECHNOLOGY (IT) PROJECT MANAGEMENT

A Practical Guide to e-learning Development Project Management

Information Resource Management Directive The USAP Security Assessment & Authorization Program

Security Awareness & Securing the Human. By: Chandos J. Carrow, CISSP System Office - Information Security Officer Virginia Community College System

Department of Veteran Affairs. Fred Catoe Office of Cyber and Information Security AAIP Project Manager March 2004

LMS Maximizing the Return on Your LMS Investment

U.S. DEPARTMENT OF THE INTERIOR OFFICE OF INSPECTOR GENERAL Verification of Previous Office of Inspector General Recommendations September 2009

Compliance Risk Management IT Governance Assurance

Publication Number: Third Draft Special Publication Revision 1. A Role Based Model for Federal Information Technology / Cyber Security Training

Statement of Danny Harris, Ph.D. Chief Information Officer U.S. Department of Education

SUMMATIVE EVALUATION REPORT (Library Media Specialist) Library Media Specialist: School: Date:

Information Technology

INFORMATION PROCEDURE

A Role-Based Model for Federal Information Technology/ Cybersecurity Training

Information Resource Management Directive USAP Information Security Awareness, Training and Education Program

NATIONAL CREDIT UNION ADMINISTRATION OFFICE OF INSPECTOR GENERAL

Elearning: Building an Effective and Engaging Solution Online

Report of Evaluation OFFICE OF INSPECTOR GENERAL. OIG 2014 Evaluation of the Farm Credit OIG 2014 Administration s. Management Act.

STATEMENT OF MARK A.S. HOUSE OF REPRESENTATIVES

IG ISCM MATURITY MODEL FOR FY 2015 FISMA FOR OFFICIAL USE ONLY

UNITED STATES COMMISSION ON CIVIL RIGHTS. Fiscal Year 2012 Federal Information Security Management Act Evaluation

Audit of the Board s Information Security Program

Evaluation: Designs and Approaches

Develop effective print and electronic resources, services, facility, and manage budget and human resource.

INFORMATION SECURITY

Department of Veterans Affairs VA HANDBOOK CONTRACT SECURITY

EDUCATION AND LEARNING DELIVERY SYSTEM

2.0 ROLES AND RESPONSIBILITIES

Federal Acquisition Service

INFORMATION DIRECTIVE GUIDANCE GUIDANCE FOR MANUALLY COMPLETING INFORMATION SECURITY AWARENESS TRAINING

Section B Standard Five T

Information Security Management

NATIONAL CREDIT UNION ADMINISTRATION OFFICE OF INSPECTOR GENERAL

Office of the Chief Information Officer Department of Energy Identity, Credential, and Access Management (ICAM)

Portal Storm: A Cyber/Business Continuity Exercise. Cyber Security Initiatives

VA Office of Inspector General

Enterprise Continuous Monitoring Bridging Shared Services, Clouds, and In-House Solutions

Southwest Riverside County Adult Education Consortium Narrative

PREFACE TO SELECTED INFORMATION DIRECTIVES CHIEF INFORMATION OFFICER MEMORANDUM

U.S. ELECTION ASSISTANCE COMMISSION OFFICE OF INSPECTOR GENERAL

Outcome-Based Evaluation for Technology Training Projects. Developed for: The New York State Library. Division of Library Development

Department of Veterans Affairs VA Directive 6004 CONFIGURATION, CHANGE, AND RELEASE MANAGEMENT PROGRAMS

Participants: Introduction:

SMITHSONIAN INSTITUTION

Computer Security Awareness Training Requirements Approved by: Deputy Administrator, Management

IT Security Handbook. Security Awareness and Training

DEPARTMENT OF VETERANS AFFAIRS VA HANDBOOK INCORPORATING SECURITY AND PRIVACY INTO THE SYSTEM DEVELOPMENT LIFE CYCLE

Improving the Way the Government Buys

น กศ กษา นายจ กรพงษ แผ นทอง ปร ญญาโท สาขา การสอนคณ ตศาสตร (ท นสควค.)

Audit of the Department of State Information Security Program

Department of Veterans Affairs VA Handbook Information Security Program

Information Resource Management Directive USAP Information Security Architecture

GAO CYBERSECURITY HUMAN CAPITAL. Initiatives Need Better Planning and Coordination

FSIS DIRECTIVE

How To Teach Math To A Grade 8

Evaluation of the Financial Stability Pathway. Results for Provider Study EXECUTIVE SUMMARY. Prepared for the Maryland CASH Campaign by

IT-CNP, Inc. Capability Statement

Massively Scaled Security Solutions for Massively Scaled IT

Online Degree Programs Comparison Guide

Learning Management. Systems...an introduction.

EPA Classification No.: CIO P-02.1 CIO Approval Date: 08/06/2012 CIO Transmittal No.: Review Date: 08/06/2015

GEARS Cyber-Security Services

DHS IT Successes. Rationalizing Our IT Infrastructure

EFFICIENT KNOWLEDGE MANAGEMENT: A PEAK PERFORMANCE SOLUTION TO STAKEHOLDER ENGAGEMENT WHITE PAPER

for Information Security

DoD Needs an Effective Process to Identify Cloud Computing Service Contracts

Middle Class Economics: Cybersecurity Updated August 7, 2015

NIST Cyber Security Activities

ACSAC NOAA/NESDIS Case Study. December, 2006

The DS Information Assurance and Cybersecurity Role-Based Training Program. Diplomatic Security Training Center (DSTC) Dunn Loring, VA

2015 VA Privacy Matters Symposium Session 2: Privacy Awareness

Information Assurance Branch (IAB) Cybersecurity Best Practice for Executive Level Managers

Strategic HR Conference Link Compensation To Values. A Discussion on What Makes Incentive Pay Plans Work. Tom Wilson Wilson Group

Information Security for Managers

1. Introduction. Chaiwat Waree and Chaiwat Jewpanich

Creating The Perfect Surgical Patient/Family Experience

Think like an MBA not a CISSP

BPMN TRAINING COURSE:

How to Use the Federal Risk and Authorization Management Program (FedRAMP) for Cloud Computing

E-learning Course Design Don McIntosh, Ph.D. - February 23, 2006

BEST PRACTICES IN CYBER SUPPLY CHAIN RISK MANAGEMENT

WHITE PAPER NEXXUS SALES. Administering MBO-based Incentive Compensation Plans

CYBERSECURITY CHALLENGES FOR DOD ACQUISITION PROGRAMS. Steve Mills DAU-South

How to use the National Cybersecurity Workforce Framework. Your Implementation Guide

2008 NASCIO Award Submission. Utilizing PCI Compliance to Improve Enterprise Risk Management

Remarks by. Carolyn G. DuChene Deputy Comptroller Operational Risk. at the

Human Capital Update

Evaluation Report. Office of Inspector General

U.S. Department of Energy Office of Inspector General Office of Audits and Inspections

Congratulations on your admission into our Program! What is the purpose of this orientation?

Transcription:

Role-Based Security Training Training and Policy Management Service Rosa C Ayer, MBA, CISSP

Table Of Contents Background Overview of the Program Choosing Roles Designing the Message Shared Topics and Themes Recommendations

Background In the past two years VA has developed several sets of awareness courses customized to specific key roles within our organization. The intent of each of these role-based courses is to increase awareness and develop a culture throughout VA where it is proactively recognized that information security is everyone s business. The courses enable individuals to recognize information security concerns and how to respond accordingly.

Overview of the Program The course framework and design are web-based training (WBT). The content is based on widely-accepted best practices in cyber security, as set forth in federal law, regulation, and the full set of NIST cyber security guidance. All courses are mandatory to meet the annual awareness training for role-specific staff as required by NIST SP 800-16. Courses are accessible through VA Learning Management System (LMS) Learners are given a pre-test, varied knowledge checks between lessons and a post-test, which they must achieve a 80% or better to receive credit.

Each course uses a unique story specific to the responsibilities of that role. We wanted to immerse learners in real-world situations that related to their role. They could experience the risks and benefits of information security. Supporting, anecdotal, and peripheral information is provided through a Flashanimated smart learning aid.

All courses include common topics and themes. How security affects the mission of the VA Managing the risk of security Integrating security needs into the capital planning process Resources and people involved to ensure the success of security programs

We used four primary techniques to develop the courses. Consistent message is communicated about the importance of information security. Consulted with subject-matter experts within VA Used guidance in NIST 800-16 Mapped NIST to VA Policy identifying roles and responsibilities

Choosing the Roles VA has identified the following specific roles as the target audience: IT Project Managers levels 101, 201 and 301 Executives and Chief Information Officers (CIOs) levels 101 and 201 IT Acquisition Personnel (Contracting Officers and Contraction Officers Technical Representatives (COTRs)) level 101 and 201 Research and Development staff - level 201 Human Resources Staff level 201 Health Care Professionals level 201 IT Staff and Software Developers levels 101, 301 and 401 More to come

Executives & CIOs 201 High Level Outline COURSE WELCOME AND NAVIGATION CONTEXT: SECURING FEDERAL INFORMATION ASSETS VA S FISMA REPORT CARD MEASURING PROGRESS IN PROTECTING VETERANS AND PRESERVING VA S IT ASSETS RECURRING DEFICIENCIES IN VA S FISMA SCORE BEST PRACTICES FOR ADDRESSING IT SECURITY DEFICIENCIES AND IMPROVING FISMA SCORE PUTTING AWARENESS INTO ACTION COURSE SUMMARY

IT Project Managers High Level Outline INTRODUCTION SETTING THE GOLD STANDARD IN INFORMATION SECURITY OVERVIEW OF RISK MANAGEMENT IN THE VA SDLC STEP 0 - RISK MANAGEMENT FOR CONCEPT DEFINITION STEP 1 - RISK MANAGEMENT FOR CONCEPT DEVELOPMENT STEP 2 - RISK MANAGEMENT FOR SYSTEM DESIGN AND PROOF OF CONCEPT STEP 3 - RISK MANAGEMENT FOR SYSTEM DEVELOPMENT AND TESTING COURSE SUMMARY

Acquisition Personnel 201 High Level Outline INTRODUCTION SETTING THE GOLD STANDARD IN INFORMATION SECURITY THE ACQUISITION AND SYSTEM DEVELOPMENT LIFE CYCLES PLANNING PHASE CONTRACTING PHASE POST-AWARD AND MONITORING PHASE FOLLOW-ON PHASE COURSE SUMMARY

The messaging goals of all courses are consistent. Focused on changing the attitudes of the learners and developing a greater sense of appreciation for the impact of security on business results. Stressed the importance of security to support and strengthen the business of the VA. Discussed compliance as a management tool to achieve necessary security goals.

Easy Access to the Courses All courses accessible through the Information Protection Portal Direct link to all training Direct link to Role-Based Courses

Compliance Results 14000 12000 10000 8000 6000 4000 Number Identified Total Staff Trained FY'06 Total Staff Trained FY'07 Total Staff Trained 2000 0 Execs CIOs IT PM Totals IT Specialists

Role-Based Training Compliance Results Agency Totals Number Identified Total Staff Trained FY'06 Total Staff Trained FY'07 Total Staff Trained Execs 1234 1618 697 2315 CIOs 299 449 1194 1643 IT PM 665 916 394 1310 IT Specialists 5606 6036 1150 7186 Totals 7804 9019 3435 12454

Follow these recommendations when developing role-based training. 1. Identify the organization s core messages for information security 2. Incorporate industry best practices (what should be done), not just what is currently done 3. Define and identify roles and responsibilities for Information security 4. Tie every action back to the why am I doing this for VA, this is to protect the veteran 5. Use story!

Avoid these situations when developing role-based training. 1. Don t just talk about what you need to do make it real, answer the why should I care? 2. Don t expect 100% buy-in even from those helping to develop the course; that s not the way we do things 3. Don t expect training alone to solve the problem; each role needs the proper incentives for doing right and disincentives for doing wrong

Role-Based Training For additional information contact Rosa Ayer (561) 753-2827 rosa.ayer@va.gov