From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,200 courses taught by industry experts.

User habits

User habits

- [Instructor] Security education programs should include a wide variety of topics related to user habits. By replacing risky habits with strong security habits, organizations reduce the likelihood that user accounts will become compromised. Let's take a look at some of the habits that security education programs should address. Security training should include coverage of password security practices. Most organizations already have a password security policy that enforces requirements such as password complexity and encryption. Security training programs should remind users of these requirements and also educate them about the importance of requirements that can't be enforced technically. For example, users should know that reusing their work password on websites, and other accounts jeopardizes security in the event that an external website is compromised. Organizations should also include data handling procedures in their security training programs. Users must know the proper ways…

Contents