Effective Security Awareness Training
Security awareness training makes everyone aware of the potential security risks and ensures adherence to security processes. It is essential to a security culture that safeguards people, information, and assets.
Determine training requirements
Section titled “Determine training requirements”Knighthood uses a consistent and structured method to determine your organisation’s training requirements.
What the training covers
Section titled “What the training covers”Security awareness training is designed to:
- Address risks identified during risk review
- Ensure compliance with security policies and processes
- Encourage employees and contractors to take personal responsibility for effective security, regardless of role or access level
Training covers the security measures in your facilities, in facilities handling your information and assets, and in places where your employees or contractors work. It includes policies and processes for:
- Personal safety
- Asset protection
- Official information protection
- Reporting — security incidents, changes in personal circumstances, and mandatory or legislative reporting requirements
- Attending security briefings when required
Who is trained
Section titled “Who is trained”Knighthood provides security awareness training and briefings to all employees and contractors based in your facilities.
Training goals
Section titled “Training goals”Everyone in the organisation needs to understand the security rules and the responsibilities that apply to their role or work area. They must also understand the threats the security measures are designed to combat, so the training sustains security rather than just describing it.
Training process
Section titled “Training process”Training programmes use a mix of delivery methods based on customer requirements, and run as an ongoing, regular part of operations.
Onboarding
Section titled “Onboarding”Include security awareness training in the onboarding process from the start.
Refreshers
Section titled “Refreshers”Regular refresher training reminds employees of security measures and alerts them to new ones.
Emergency, safety, or security roles
Section titled “Emergency, safety, or security roles”People in emergency, safety, or security roles receive extra training so they can help keep everyone safe in a threat, and run exercises to practise their skills and confirm ongoing competence.
Communication
Section titled “Communication”Stay engaged about security measures between formal training sessions:
- Run security campaigns to address ongoing needs or special requirements tied to sensitive areas, activities, or timeframes
- Broadcast security processes and hints through publications, electronic bulletins, and visual displays such as posters
- Conduct security drills and exercises
- Include security questions in job interviews
- Include security attitudes and performance in the performance management programme
Employee safety handbook
Section titled “Employee safety handbook”Create an Employee Safety Handbook and make it readily available to everyone. It should include emergency response guidelines and contact information, safety requirements and procedures, and safety measures for areas of heightened risk such as public areas.
Protecting assets
Section titled “Protecting assets”Everyone should know how to safeguard the organisation’s assets. Before granting access, provide training on:
- Using access control systems and other methods to secure assets
- Complying with legal requirements for protecting assets
- Reporting lost, damaged, or stolen assets
- Following audit and inventory protocols for assets
Reporting security concerns
Section titled “Reporting security concerns”Create an internal process for reporting security concerns and train everyone to report the risks they encounter — for example:
- Suspicious behaviour
- Threatening behaviour communicated through letters, bomb threats, and phone calls
- Lost, stolen, or broken security equipment
- Security infringements and breaches
- Full secure waste bins
- Lost identity or credit cards
- Lost protectively marked or official material
- Serious wrongdoing (within the organisation or another)
