36 MAC Pt. 1, R. 5.1

User Awareness Education and Training

Year: 2026Length: 527 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 5.1

User Awareness Education and Training A. Each agency must ensure all employees, associates, business partners, and others using SOM systems and data are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems and data. B. Each agency must implement and maintain a security awareness training program for all agency users (including managers, senior executives, and contractors) to educate them on how to interact with SOM systems and data in a secure manner. 1. Conduct training at hire and, at a minimum, annually. 2. Train agency users to recognize social engineering attacks, such as phishing, pre-texting, and tailgating. 3. Train workforce members on authentication best practices. Example topics include MFA, password composition, and credential management. 4. Train workforce members on how to identify and properly store, transfer, archive, and destroy sensitive data. This also includes training workforce members on clear screen and desk best practices, such as locking their screen when they step away from their enterprise asset, erasing physical and virtual whiteboards at the end of meetings, and storing data and assets securely. 5. Train workforce members to be able to recognize a potential incident and be able to report such an incident. 6. Train workforce to understand how to verify and report out-of-date software patches or any failures in automated processes and tools. Part of this training should include notifying IT personnel of any failures in automated processes and tools. 7. Train workforce members on the dangers of connecting to, and transmitting data over, insecure networks for enterprise activities. If the enterprise has remote workers, training must include guidance to ensure that all users securely configure their home network infrastructure. 8. Ensure that the security awareness program and related content is updated frequently (at least annually) to address new technologies, threats, standards and business requirements. 9. Train workforce members to be aware of causes for unintentional data exposure. Example topics include mis-delivery of sensitive data, losing a portable end-user device, exposing sensitive data in artificial intelligence models, or publishing data to unintended audiences. 10. Each agency must determine the method of training, weighing the convenience of computer-based training against the value of live classroom training. i. Agencies electing to use computer-based training must adhere to the enterprise standard for security awareness and education training. More information about enterprise standards can be found on ITS’s website. C. Each agency must ensure that users are trained to carry out their assigned cybersecurity-related duties and responsibilities. 1. Conduct role-specific security awareness and skills training. Example implementations include secure system administration courses for IT professionals, OWASP® Top 10 vulnerability awareness and prevention training for web application developers, advanced social engineering awareness training for high-profile roles, and specific training for personnel who maintain or secure operational technology (OT) as part of their regular duties. OT encompasses the hardware and machines responsible for the physical security processes. 2. ITS recommends each agency train personnel responsible for IT and OT assets on how to effectively respond to OT cyber incidents. D. Each agency must provide security awareness training on recognizing and reporting potential indicators of insider threats.
36 MAC Pt. 1, R. 5.1: User Awareness Education and Training | Justis AI