All courses

Information System Security Awareness

Information Security, Physical Security, Removable Media, Wi-Fi & VPN, Clean Desk, Mobile Devices, remote Work Storing passwords

EnglishIS Security40 AED

Price per attendee · VAT added at payment

About this course

=========================================

Mobile Devices

Slide 1

Mobile Devices

Mobile devices allow us to stay connected on the go, but hackers see this as an opportunity to catch you off guard.

Slide 2

Why It Matters

Mobile devices have more access to sensitive information than ever before, and our reliance on their capabilities increases every year.

Slide 3

Unattended Devices

You should always know where your devices are and who could potentially have access to them. Laptops, phones, tablets, and other mobile devices should always be locked up and stored in a secure place when unattended.

Slide 4

Strong Passcodes

Passcodes are the first line of defense if your device is lost or stolen. Don’t use a simple passcode such as your birthdate, street address, or anything else that’s easy to guess. When possible, use fingerprint, facial recognition, or other strong authentication methods for your device.

Slide 5

More Capable Than Ever

Whether you’re checking email, getting directions, or even paying for lunch, it’s clear that we now use our mobile devices for more than just making calls. Take a moment to consider all the things a hacker could do or see if they had access to your mobile device.

Slide 6

Stay Current

Mobile devices need to be updated with the latest security patches to help defend against the latest security threats. Your organization should have a process to keep your mobile devices updated with the latest security patches.

Slide 7

Wi-Fi & Bluetooth

Wi-Fi and Bluetooth technologies are very useful, but can also provide hackers with an easy access point to your device. When you’re not actively using Wi-Fi or Bluetooth, turn them off.

Slide 8

Remote Wipe

Many mobile devices offer a “remote wipe” feature, which allows your organization to remotely remove all sensitive data from your device. Contact your IT department immediately in the event your mobile device is ever lost, stolen, or seems to have been tampered with.

Slide 9

Reset Email Password

As long as someone has access to your email inbox they can reset your passwords and access your other online accounts. If your mobile device has been lost or stolen, resetting your email password is critical to preventing further damage.

Slide 10

Notify Immediately

Contact your IT department in the event your mobile device is ever lost, stolen, or seems to have been tampered with. Your organization should have procedures in place to help you respond in these scenarios.

Slide 11

Strong Passcodes

Your passcode is a great way to protect your mobile device and data. Be sure to always use strong passcodes on all your devices. Never use your birthdate or something a stranger could easily guess.

Slide 12

Unattended Devices

Always know where your devices are located, and who could potentially have access to them. Laptops, phones, tablets, and other mobile devices should always be locked up and stored in a secure place when unattended.

Slide 13

Your Role

The capabilities our mobile devices have today are incredible. Now you know the vital role you play in keeping them protected. Security is always important, even when you’re out of the office and on the go

=================================================================

Information Security

The practice of defending digital information from unauthorized access, use, disclosure, modification, or destruction. Translation, keeping your data secure.

Why is it important?

Securing information, or data, is critical because so much of an organization’s value is derived from the data it holds. Additionally, most, if not all organizations have a legal obligation to protect the data of their stakeholders, partners, and customers.

Sensitive Data

Sensitive data is generally considered anything that, if exposed, would have a negative impact on the organization financially, legally, or even simply by public embarrassment. Let’s look at some examples of sensitive data.

Personally Identifiable Information

Also known as PII, personally identifiable information is any data that could potentially identify a specific individual. Things like social security numbers, banking, or health information, but even a simple name, address, or phone number are considered sensitive data.

Intellectual Property

Also known as IP, intellectual property is data that can be protected by law through patents, copyright, or trademarks. Things like inventions, formulas, designs, or even research owned by an organization is considered sensitive data.

Proprietary Information

While not necessarily able to be copyrighted or patented, proprietary information is anything that provides a competitive advantage to an organization. Things like sales data, corporate strategies, third-party contracts, architecture design, or financial arrangements are all considered highly sensitive data.

Major Consequences

As we just saw, information that falls in the wrong hands could have major consequences. The leaked video exposed critical information about the hoverboard project.

Data Loss Prevention

Data loss prevention, or DLP for short, is a term referring to software that helps prevent users from sending sensitive data outside the organization. It scans emails and other messaging platforms for sensitive data, then blocks that data before it can be shared to others.

Information Security Program

Most organizations have what is known as an “Information Security Program” to help guide the key strategies of securing data. Next, we'll take a look at some key principles and how they can help protect your organization.

Categorizing

Your ability to properly determine the sensitivity of your organization’s data is critical to understanding information security.

Storing

Where and how you store data, even temporarily, is critical. Consider who needs access to that data and who else could potentially access it.

Sharing

Having access to sensitive data is a privilege. You should be cautious when sharing data with others, especially those outside of your organization.

Disposal

Getting rid of data is not always as easy as it sounds. You should be familiar with the processes and procedures for disposing sensitive data within your organization.

Yours, Role

Exposing data, even unintentionally, has no “Edit --> Undo”. Once information is exposed, it cannot be undone. Now you understand how valuable securing information is, the impact of losing sensitive data, and the important role you play in protecting it.

=================================================================

Clean Desk

What is a Clean Desk Program?

A Clean Desk program specifies how your organization manages physical access to sensitive information and workspaces.


Why It Matters

Sensitive information surrounds us every day, and you never know who may be trying to gain access to it.

When protecting sensitive documents, controlling physical access is just as important as controlling digital access.


Dumpster Diving

Dumpster diving is when a hacker searches through trash looking for sensitive information that has not been properly destroyed.

This information may then be used to further target an organization.


Device Locking

You should always lock your computer when leaving it unattended, regardless of your location.

This prevents anyone, including fellow employees, from:

  • Viewing your data

  • Accessing your device

  • Misusing your account


Information Disposal

Any information thrown away improperly may be used to target your organization.

Examples include:

  • Customer names

  • Billing information

  • Account numbers

  • Internal documents

Sensitive information should always be disposed of properly.


Safe Storage

Think about who may have access to your:

  • Building

  • Office

  • Workspace

Always keep sensitive documents physically protected in a safe and secure place when not in use.


Out of Office

When working outside your office, never leave sensitive documents unattended.

Even a short absence can expose confidential information.


Lock It Up

Whenever you leave your workspace, even briefly:

  • Lock your computer

  • Secure mobile devices

  • Protect access to sensitive information


Safe Disposal

When disposing of sensitive information:

  • Follow organizational policies and procedures

  • Shred confidential documents before disposal whenever required


Out of Sight

Be mindful of who may have access to your:

  • Workspace,Computer,

  • Documents

Sensitive documents should always be stored securely and physically locked away when not in use.


Your Role

A successful Clean Desk program requires effort from every employee.

You play an important role in physically protecting your organization’s sensitive information

=================================================================

Wi-Fi & VPN

Wi-Fi

Wi-Fi networks have made our lives much easier, helping us connect all of our devices to the Internet without cables.


Why It Matters

Whether you’re at work, home, or almost anywhere else, Wi-Fi networks are all around you.

But just because free Wi-Fi is available, doesn’t mean that you should trust connecting to it.


Wi-Fi Loves To Talk

When Wi-Fi is turned on, your device is constantly looking for a network to connect to, even without you knowing.

Consider disabling Wi-Fi on your device when it is not in use.


Before Connecting

Joining a Wi-Fi network is all about trust.

Before connecting, ask yourself:

  • Do I really know who owns this network?

  • Who else may have access to this network?


VPN

A Virtual Private Network (VPN) prevents hackers from being able to read your data and connection details.


Turn It Off

When not in use, you should always turn your Wi-Fi off.

This helps prevent your device from automatically connecting to unknown Wi-Fi networks.


Private Connections

When in doubt, use:

  • Your mobile phone

  • A personal hotspot

This is a safer way to access the Internet compared to using public Wi-Fi networks.


Cautiously Connect

Connecting to unknown public Wi-Fi networks should always be a last resort.

Whenever possible, use:

  • Mobile data

  • Personal hotspots

instead of open public networks.


Working Remotely

Think about all of the data you transmit when working remotely.

Be mindful of sensitive data and always take the proper measures to ensure its security.


Use a VPN

Virtual Private Networks use encryption to prevent hackers from viewing your online communications.

Consider using a VPN when connecting to a public Wi-Fi network to protect your privacy and data security.


Your Role

You can’t do much without an Internet connection these days, and Wi-Fi helps keep us connected wherever we go.

Use what you learned about Wi-Fi networks to help protect yourself and your organization from hackers.

Remember:

“Free Wi-Fi” does not mean “Safe Wi-Fi.”

============================================================================================================

Removable Media

What is Removable Media?

Removable media is a storage device used to transfer or move data from one computer to another. USB drives, CDs, DVDs, and external hard drives are common examples.


Location

Hackers often plant infected USB drives and other types of removable media at various locations around organizations. Parking lots, local coffee shops, or other public locations are common drop zones.


Appearance

Unknown devices might be sealed in what appears to be brand new packaging or even have your organization’s logo printed on them. Remember, hackers will do whatever it takes, so be suspicious regardless of appearance.


Hacker’s Goal

The hacker’s goal is to trick you into installing malware on your computer, which can:

  • Destroy data

  • Steal sensitive information

  • Perform other malicious actions


Responsible Use

At some point you might need to use removable media within your organization, but it’s important to do so responsibly. Consider:

  • The sensitivity of the data you are handling

  • Who has access to it


Ask Yourself

Are you doing your part to help protect removable media within your organization?

Are you storing sensitive data like:

  • Customer records

  • Financial data

  • Personal information

Think about the damage that could be caused if this information was lost or stolen.


Management

Just like the keys to your home, you need to know where your organization’s removable media devices are and who has access to them.

You should be aware of your organization’s policy on removable media management.


Encrypt

If lost or stolen, unprotected sensitive data on removable media devices could be accessed by anyone, including hackers.

Encrypting your data is the best way to protect it.


Don’t Connect

If you find an unknown USB drive or any other type of removable media:

  • Do NOT connect it to your computer

  • Notify your IT department immediately

  • Even if it appears harmless, treat it as suspicious


Your Role

You now understand the risks associated with removable media and how you can help protect your:

  • Friends

  • Colleagues

  • Organization

Notify your IT department right away if you find removable media that doesn’t belong to yo

================================================================================================

Physical Security

Introduction

Physical security protects people, property, and information assets from damage, unauthorized access, theft, or harm.

It is an essential part of organizational security and helps maintain a safe and secure working environment.


Strong physical security helps reduce these risks and protects both people and information.


Tailgating

Tailgating happens when an unauthorized person follows an authorized person through a secure door without permission or without being noticed.

Example:

A person quickly enters through a secure door before it closes.

Best Practice:

  • Ensure every individual uses their own access credentials.

  • Politely stop unknown persons and direct them to the proper access point.

  • Report suspicious access attempts.


Piggybacking

Piggybacking occurs when an authorized person knowingly allows another individual to enter a secure area without following access procedures.

Example:

Holding a secure door open for someone without verifying their access.

Best Practice:

  • Never allow entry without badge verification.

  • Ask coworkers and visitors to scan their own access badge.


Scan Your Badge

Access badges can be copied or misused.

Every employee must:

  • Scan their own badge

  • Never bypass access controls

  • Ensure badge scanners are used correctly

Badge scanning confirms identity and protects secure areas.


Access Badges

Employees must:

  • Keep badges secure at all times

  • Know where their badge is

  • Never lend or share badges

  • Report lost or stolen badges immediately

Badge misuse may lead to unauthorized access.


Physical Security Policy

Every organization should maintain a Physical Security Policy outlining procedures for secure areas.

Employees should:

  • Know where the policy is located

  • Understand the procedures

  • Follow all requirements

Policies support consistent security practices.


Follow Procedures

Security procedures work only when everyone follows them.

Examples of non-compliance:

  • Sharing access badges

  • Allowing unauthorized entry

  • Ignoring security procedures

Even small actions can create major security risks.


Don’t Prop Doors Open

Secure doors must never be left open.

A propped door can allow unauthorized access.

If you see a door propped open:

  • Remove the object

  • Close the door immediately

  • Report the incident


Report Security Incidents

Always report physical security incidents.

Examples include:

  • Unauthorized persons in secure areas

  • Lost access badges

  • Propped doors

  • Suspicious activity

Reporting helps protect the organization and allows quick action.


Your Role

Physical security is everyone’s responsibility.

You can help by:

  • Following access procedures

  • Using your badge properly

  • Keeping secure doors closed

  • Reporting incidents promptly

  • Supporting a safe working environment

u and never plug in a device without IT approval.

What you'll learn

  1. 1

    Information Security

    Information Security The practice of defending digital information from unauthorized access, use, disclosure, modification, or destruction. Translation, keeping your data secure.

    4 minutes

  2. 2

    Physical Security

    To protect people, property, and information assets from damage or harm.

    4 minutes

  3. 3

    Removable Media

    Removable media is a storage device used to transfer or move data from one computer to another. USB drives, CDs, DVDs, and external hard drives are all common examples.

    4 minutes

  4. 4

    Wi-Fi & VPN

    Wi-Fi networks have made our lives much easier, helping us connect all of our devices to the Internet without cables.

    4 minutes

  5. 5

    Clean Desk

    A clean desk program specifies how your organization manages physical access to sensitive information and workspaces.

    4 minutes

  6. 6

    Mobile Devices

    Mobile devices allow us to stay connected on the go, but hackers see this as an opportunity to catch you off guard.

    3 minutes

  7. 7

    Remote Work

    With more and more people working outside the office, you need to be aware of the unique risks associated with working remotely.

    3 minutes

  8. 8

    Storing passwords

    A password is simply a secret word or phrase that is used to get access to something.

    6 minutes

  9. 9

    Locking Devices

    When leaving any of your devices unattended, it’s crucial to make sure that you have locked or logged out of them.

    4 minutes

  10. 10

    Social Media handles

    Social media virtually connects people around the world. But with all of this accessible information, it has become a playground for hackers to target us.

    5 minutes

Need the full ADHICS compliance lifecycle — governance, risk, audit and training at enterprise scale? Explore GRSCIA