Internet Security Awareness Training (ISAT), also known as Security Education, Training, and Awareness (SETA), is a training program administered to the members of a cybersecurity organization. ISAT is a subset of general security awareness training (SAT), focused on internet security awareness.
Cybersecurity organizations that need to comply with government regulations (e.g., the Gramm–Leach–Bliley Act, the Payment Card Industry Data Security Standard, Health Insurance Portability and Accountability Act, Sarbanes–Oxley Act) normally require formal annual SAT training for all employees. Small and medium enterprises (SME) are generally recommended to provide training. Training is often administered in the form of online courses. ISAT organizations train and create awareness of information security management within their environment. The ISAT program target must be based on user roles within organizations and, for positions that expose the organizations to increased risk levels, specialized courses must be required.
Coverage Although there are general topics to cover for the training, it is necessary for each organization to have a coverage strategy based on their needs to ensure the training is practical and captures critical topics relevant to the organization. As the threat landscape changes very frequently, organizations should continuously review their training programs to ensure relevance with current trends. Topics covered in ISAT include:
Appropriate methods for protecting sensitive information on personal computer systems, such as password policy. Various computer security concerns, including spam, malware, phishing, social engineering, etc. Consequences of failure to properly protect information, such as potential job loss, economic consequences to the firm, damage to individuals whose private records are divulged and possible civil and criminal law penalties. Being Internet Security aware means understanding that there are people actively trying to steal data that is stored within the organization's computers (often in search of usernames and passwords that will grant access to bank accounts and other high-value IT assets) and that it is important to protect this data. The scope of general training should include topics such as password security, email phishing, social engineering, mobile device security, sensitive data security and business communications. When specialized knowledge is required, employees are usually required to take technical and in-depth training courses. If an organization determines that it is best to use one of the available training tools on the market, it must ensure the training offered by this tool can meet set objectives, such as providing employees with the knowledge to understand risks and the behaviors needed in managing them, as well as actions to take to prevent or detect security incidents. Other objectives may be to ensure the training will use language easily understandable by the trainees and that the pricing is reasonable. Organizations are recommended to base ISAT training content on employee roles and their culture; the policy should guide that training for all employees. The following are examples of sources of reference materials:
National Institute of Standards and Technology (NIST) Special Publication 800-50, Building an Information Technology Security Awareness and Training Program International Standards Organization (ISO) 27002:2013, Information technology—Security techniques—Code of practice for information security controls International Standards Organization (ISO) 27001:2013, Information technology — Security techniques — Information security management systems COBIT 5 Appendix F.2, Detailed Guidance: Services, Infrastructure and Applications Enabler, Security Awareness The training must focus on current threats specific to an organization and the impacts that materialize as a result of user actions. Including practical examples and ways of dealing with scenarios can help users learn the appropriate measures to take. It is good practice to periodically train customers of specific organizations on threats they face from people with malicious intentions. Coverage strategy for SAT should be driven by an organization's policy. It can help truly determine the level of depth of the training and where it should be conducted at a global level, a business unit level, or a combination of both. A policy also empowers a responsible party within the organization to run the training.
Importance Studies show that well-structured security awareness training can significantly reduce the likelihood of cyber incidents caused by human error. According to the Ponemon Institute, organizations that implement regular security training experience up to 70% fewer successful phishing attacks. Additionally, a 2023 Verizon Data Breach Investigations Report found that 74% of breaches involve the human element, highlighting the need for continuous education. Employees are key in whether organizations are breached or not; there must be a policy on creating awareness and training them on emerging threats and actions to take in safeguarding sensitive information and reporting any observed unusual activity within the corporate environment. Research has shown that SAT has helped reduce cyberattacks within organizations, especially when it comes to phishing, as trainees learned to identify these attack modes and give them the self-assurance to take action appropriately. There is an increase in phishing attacks, and it has become increasingly important for people to understand how these attacks work, and the actions required to prevent them, and SAT has shown a significant impact on the number of successful phishing attacks against organizations.
Compliance requirements Various regulations and laws mandate SAT for organizations in specific industries, including the Gramm–Leach–Bliley Act (GLBA) for the financial services, the Federal Information Security Modernization Act of 2014 for federal agencies, and the European Union's General Data Protection Regulation (GDPR).
Federal Information Security Modernization Act Employees and contractors in federal agencies are required to receive Security Awareness Training annually. The program needs to address job-related information security risks linked that provide them with the knowledge to lessen security risks.
… excerpt ends here. Continue reading the full article.


