36 MAC Pt. 1, R. 5.1
User Awareness Education and Training
Cite as 36 Miss. Admin. Code Pt. 1, R. 5.1
User Awareness Education and Training
A. Each agency must ensure all employees, associates, business partners, and others
using SOM systems and data are made aware of the security risks associated with
their activities and of the applicable policies, standards, and procedures related to the
security of those systems and data.
B. Each agency must implement and maintain a security awareness training program for
all agency users (including managers, senior executives, and contractors) to educate
them on how to interact with SOM systems and data in a secure manner.
1. Conduct training at hire and, at a minimum, annually.
2. Train agency users to recognize social engineering attacks, such as phishing,
pre-texting, and tailgating.
3. Train workforce members on authentication best practices. Example topics
include MFA, password composition, and credential management.
4. Train workforce members on how to identify and properly store, transfer,
archive, and destroy sensitive data. This also includes training workforce
members on clear screen and desk best practices, such as locking their screen
when they step away from their enterprise asset, erasing physical and virtual
whiteboards at the end of meetings, and storing data and assets securely.
5. Train workforce members to be able to recognize a potential incident and be
able to report such an incident.
6. Train workforce to understand how to verify and report out-of-date software
patches or any failures in automated processes and tools. Part of this training
should include notifying IT personnel of any failures in automated processes
and tools.
7. Train workforce members on the dangers of connecting to, and transmitting
data over, insecure networks for enterprise activities. If the enterprise has
remote workers, training must include guidance to ensure that all users
securely configure their home network infrastructure.
8. Ensure that the security awareness program and related content is updated
frequently (at least annually) to address new technologies, threats, standards
and business requirements.
9. Train workforce members to be aware of causes for unintentional data
exposure. Example topics include mis-delivery of sensitive data, losing a
portable end-user device, exposing sensitive data in artificial intelligence
models, or publishing data to unintended audiences.
10. Each agency must determine the method of training, weighing the
convenience of computer-based training against the value of live classroom
training.
i.
Agencies electing to use computer-based training must adhere to the
enterprise standard for security awareness and education training.
More information about enterprise standards can be found on ITS’s
website.
C. Each agency must ensure that users are trained to carry out their assigned
cybersecurity-related duties and responsibilities.
1. Conduct role-specific security awareness and skills training. Example
implementations include secure system administration courses for IT
professionals, OWASP® Top 10 vulnerability awareness and prevention
training for web application developers, advanced social engineering
awareness training for high-profile roles, and specific training for personnel
who maintain or secure operational technology (OT) as part of their regular
duties. OT encompasses the hardware and machines responsible for the
physical security processes.
2. ITS recommends each agency train personnel responsible for IT and OT
assets on how to effectively respond to OT cyber incidents.
D. Each agency must provide security awareness training on recognizing and reporting
potential indicators of insider threats.