Information System Security Awareness
Information Security, Physical Security, Removable Media, Wi-Fi & VPN, Clean Desk, Mobile Devices, remote Work Storing passwords
Price per attendee · VAT added at payment
About this course
=========================================
Mobile Devices
Slide 1
Mobile Devices
Mobile devices allow us to stay connected on the go, but hackers see this as an opportunity to catch you off guard.
Slide 2
Why It Matters
Mobile devices have more access to sensitive information than ever before, and our reliance on their capabilities increases every year.
Slide 3
Unattended Devices
You should always know where your devices are and who could potentially have access to them. Laptops, phones, tablets, and other mobile devices should always be locked up and stored in a secure place when unattended.
Slide 4
Strong Passcodes
Passcodes are the first line of defense if your device is lost or stolen. Don’t use a simple passcode such as your birthdate, street address, or anything else that’s easy to guess. When possible, use fingerprint, facial recognition, or other strong authentication methods for your device.
Slide 5
More Capable Than Ever
Whether you’re checking email, getting directions, or even paying for lunch, it’s clear that we now use our mobile devices for more than just making calls. Take a moment to consider all the things a hacker could do or see if they had access to your mobile device.
Slide 6
Stay Current
Mobile devices need to be updated with the latest security patches to help defend against the latest security threats. Your organization should have a process to keep your mobile devices updated with the latest security patches.
Slide 7
Wi-Fi & Bluetooth
Wi-Fi and Bluetooth technologies are very useful, but can also provide hackers with an easy access point to your device. When you’re not actively using Wi-Fi or Bluetooth, turn them off.
Slide 8
Remote Wipe
Many mobile devices offer a “remote wipe” feature, which allows your organization to remotely remove all sensitive data from your device. Contact your IT department immediately in the event your mobile device is ever lost, stolen, or seems to have been tampered with.
Slide 9
Reset Email Password
As long as someone has access to your email inbox they can reset your passwords and access your other online accounts. If your mobile device has been lost or stolen, resetting your email password is critical to preventing further damage.
Slide 10
Notify Immediately
Contact your IT department in the event your mobile device is ever lost, stolen, or seems to have been tampered with. Your organization should have procedures in place to help you respond in these scenarios.
Slide 11
Strong Passcodes
Your passcode is a great way to protect your mobile device and data. Be sure to always use strong passcodes on all your devices. Never use your birthdate or something a stranger could easily guess.
Slide 12
Unattended Devices
Always know where your devices are located, and who could potentially have access to them. Laptops, phones, tablets, and other mobile devices should always be locked up and stored in a secure place when unattended.
Slide 13
Your Role
The capabilities our mobile devices have today are incredible. Now you know the vital role you play in keeping them protected. Security is always important, even when you’re out of the office and on the go
=================================================================
Information Security
The practice of defending digital information from unauthorized access, use, disclosure, modification, or destruction. Translation, keeping your data secure.
Why is it important?
Securing information, or data, is critical because so much of an organization’s value is derived from the data it holds. Additionally, most, if not all organizations have a legal obligation to protect the data of their stakeholders, partners, and customers.
Sensitive Data
Sensitive data is generally considered anything that, if exposed, would have a negative impact on the organization financially, legally, or even simply by public embarrassment. Let’s look at some examples of sensitive data.
Personally Identifiable Information
Also known as PII, personally identifiable information is any data that could potentially identify a specific individual. Things like social security numbers, banking, or health information, but even a simple name, address, or phone number are considered sensitive data.
Intellectual Property
Also known as IP, intellectual property is data that can be protected by law through patents, copyright, or trademarks. Things like inventions, formulas, designs, or even research owned by an organization is considered sensitive data.
Proprietary Information
While not necessarily able to be copyrighted or patented, proprietary information is anything that provides a competitive advantage to an organization. Things like sales data, corporate strategies, third-party contracts, architecture design, or financial arrangements are all considered highly sensitive data.
Major Consequences
As we just saw, information that falls in the wrong hands could have major consequences. The leaked video exposed critical information about the hoverboard project.
Data Loss Prevention
Data loss prevention, or DLP for short, is a term referring to software that helps prevent users from sending sensitive data outside the organization. It scans emails and other messaging platforms for sensitive data, then blocks that data before it can be shared to others.
Information Security Program
Most organizations have what is known as an “Information Security Program” to help guide the key strategies of securing data. Next, we'll take a look at some key principles and how they can help protect your organization.
Categorizing
Your ability to properly determine the sensitivity of your organization’s data is critical to understanding information security.
Storing
Where and how you store data, even temporarily, is critical. Consider who needs access to that data and who else could potentially access it.
Sharing
Having access to sensitive data is a privilege. You should be cautious when sharing data with others, especially those outside of your organization.
Disposal
Getting rid of data is not always as easy as it sounds. You should be familiar with the processes and procedures for disposing sensitive data within your organization.
Yours, Role
Exposing data, even unintentionally, has no “Edit --> Undo”. Once information is exposed, it cannot be undone. Now you understand how valuable securing information is, the impact of losing sensitive data, and the important role you play in protecting it.
=================================================================
Clean Desk
What is a Clean Desk Program?
A Clean Desk program specifies how your organization manages physical access to sensitive information and workspaces.
Why It Matters
Sensitive information surrounds us every day, and you never know who may be trying to gain access to it.
When protecting sensitive documents, controlling physical access is just as important as controlling digital access.
Dumpster Diving
Dumpster diving is when a hacker searches through trash looking for sensitive information that has not been properly destroyed.
This information may then be used to further target an organization.
Device Locking
You should always lock your computer when leaving it unattended, regardless of your location.
This prevents anyone, including fellow employees, from:
Viewing your data
Accessing your device
Misusing your account
Information Disposal
Any information thrown away improperly may be used to target your organization.
Examples include:
Customer names
Billing information
Account numbers
Internal documents
Sensitive information should always be disposed of properly.
Safe Storage
Think about who may have access to your:
Building
Office
Workspace
Always keep sensitive documents physically protected in a safe and secure place when not in use.
Out of Office
When working outside your office, never leave sensitive documents unattended.
Even a short absence can expose confidential information.
Lock It Up
Whenever you leave your workspace, even briefly:
Lock your computer
Secure mobile devices
Protect access to sensitive information
Safe Disposal
When disposing of sensitive information:
Follow organizational policies and procedures
Shred confidential documents before disposal whenever required
Out of Sight
Be mindful of who may have access to your:
Workspace,Computer,
Documents
Sensitive documents should always be stored securely and physically locked away when not in use.
Your Role
A successful Clean Desk program requires effort from every employee.
You play an important role in physically protecting your organization’s sensitive information
=================================================================
Wi-Fi & VPN
Wi-Fi
Wi-Fi networks have made our lives much easier, helping us connect all of our devices to the Internet without cables.
Why It Matters
Whether you’re at work, home, or almost anywhere else, Wi-Fi networks are all around you.
But just because free Wi-Fi is available, doesn’t mean that you should trust connecting to it.
Wi-Fi Loves To Talk
When Wi-Fi is turned on, your device is constantly looking for a network to connect to, even without you knowing.
Consider disabling Wi-Fi on your device when it is not in use.
Before Connecting
Joining a Wi-Fi network is all about trust.
Before connecting, ask yourself:
Do I really know who owns this network?
Who else may have access to this network?
VPN
A Virtual Private Network (VPN) prevents hackers from being able to read your data and connection details.
Turn It Off
When not in use, you should always turn your Wi-Fi off.
This helps prevent your device from automatically connecting to unknown Wi-Fi networks.
Private Connections
When in doubt, use:
Your mobile phone
A personal hotspot
This is a safer way to access the Internet compared to using public Wi-Fi networks.
Cautiously Connect
Connecting to unknown public Wi-Fi networks should always be a last resort.
Whenever possible, use:
Mobile data
Personal hotspots
instead of open public networks.
Working Remotely
Think about all of the data you transmit when working remotely.
Be mindful of sensitive data and always take the proper measures to ensure its security.
Use a VPN
Virtual Private Networks use encryption to prevent hackers from viewing your online communications.
Consider using a VPN when connecting to a public Wi-Fi network to protect your privacy and data security.
Your Role
You can’t do much without an Internet connection these days, and Wi-Fi helps keep us connected wherever we go.
Use what you learned about Wi-Fi networks to help protect yourself and your organization from hackers.
Remember:
“Free Wi-Fi” does not mean “Safe Wi-Fi.”
============================================================================================================
Removable Media
What is Removable Media?
Removable media is a storage device used to transfer or move data from one computer to another. USB drives, CDs, DVDs, and external hard drives are common examples.
Location
Hackers often plant infected USB drives and other types of removable media at various locations around organizations. Parking lots, local coffee shops, or other public locations are common drop zones.
Appearance
Unknown devices might be sealed in what appears to be brand new packaging or even have your organization’s logo printed on them. Remember, hackers will do whatever it takes, so be suspicious regardless of appearance.
Hacker’s Goal
The hacker’s goal is to trick you into installing malware on your computer, which can:
Destroy data
Steal sensitive information
Perform other malicious actions
Responsible Use
At some point you might need to use removable media within your organization, but it’s important to do so responsibly. Consider:
The sensitivity of the data you are handling
Who has access to it
Ask Yourself
Are you doing your part to help protect removable media within your organization?
Are you storing sensitive data like:
Customer records
Financial data
Personal information
Think about the damage that could be caused if this information was lost or stolen.
Management
Just like the keys to your home, you need to know where your organization’s removable media devices are and who has access to them.
You should be aware of your organization’s policy on removable media management.
Encrypt
If lost or stolen, unprotected sensitive data on removable media devices could be accessed by anyone, including hackers.
Encrypting your data is the best way to protect it.
Don’t Connect
If you find an unknown USB drive or any other type of removable media:
Do NOT connect it to your computer
Notify your IT department immediately
Even if it appears harmless, treat it as suspicious
Your Role
You now understand the risks associated with removable media and how you can help protect your:
Friends
Colleagues
Organization
Notify your IT department right away if you find removable media that doesn’t belong to yo
================================================================================================
Physical Security
Introduction
Physical security protects people, property, and information assets from damage, unauthorized access, theft, or harm.
It is an essential part of organizational security and helps maintain a safe and secure working environment.
Strong physical security helps reduce these risks and protects both people and information.
Tailgating
Tailgating happens when an unauthorized person follows an authorized person through a secure door without permission or without being noticed.
Example:
A person quickly enters through a secure door before it closes.
Best Practice:
Ensure every individual uses their own access credentials.
Politely stop unknown persons and direct them to the proper access point.
Report suspicious access attempts.
Piggybacking
Piggybacking occurs when an authorized person knowingly allows another individual to enter a secure area without following access procedures.
Example:
Holding a secure door open for someone without verifying their access.
Best Practice:
Never allow entry without badge verification.
Ask coworkers and visitors to scan their own access badge.
Scan Your Badge
Access badges can be copied or misused.
Every employee must:
Scan their own badge
Never bypass access controls
Ensure badge scanners are used correctly
Badge scanning confirms identity and protects secure areas.
Access Badges
Employees must:
Keep badges secure at all times
Know where their badge is
Never lend or share badges
Report lost or stolen badges immediately
Badge misuse may lead to unauthorized access.
Physical Security Policy
Every organization should maintain a Physical Security Policy outlining procedures for secure areas.
Employees should:
Know where the policy is located
Understand the procedures
Follow all requirements
Policies support consistent security practices.
Follow Procedures
Security procedures work only when everyone follows them.
Examples of non-compliance:
Sharing access badges
Allowing unauthorized entry
Ignoring security procedures
Even small actions can create major security risks.
Don’t Prop Doors Open
Secure doors must never be left open.
A propped door can allow unauthorized access.
If you see a door propped open:
Remove the object
Close the door immediately
Report the incident
Report Security Incidents
Always report physical security incidents.
Examples include:
Unauthorized persons in secure areas
Lost access badges
Propped doors
Suspicious activity
Reporting helps protect the organization and allows quick action.
Your Role
Physical security is everyone’s responsibility.
You can help by:
Following access procedures
Using your badge properly
Keeping secure doors closed
Reporting incidents promptly
Supporting a safe working environment
u and never plug in a device without IT approval.
What you'll learn
- 1
Information Security
Information Security The practice of defending digital information from unauthorized access, use, disclosure, modification, or destruction. Translation, keeping your data secure.
4 minutes
- 2
Physical Security
To protect people, property, and information assets from damage or harm.
4 minutes
- 3
Removable Media
Removable media is a storage device used to transfer or move data from one computer to another. USB drives, CDs, DVDs, and external hard drives are all common examples.
4 minutes
- 4
Wi-Fi & VPN
Wi-Fi networks have made our lives much easier, helping us connect all of our devices to the Internet without cables.
4 minutes
- 5
Clean Desk
A clean desk program specifies how your organization manages physical access to sensitive information and workspaces.
4 minutes
- 6
Mobile Devices
Mobile devices allow us to stay connected on the go, but hackers see this as an opportunity to catch you off guard.
3 minutes
- 7
Remote Work
With more and more people working outside the office, you need to be aware of the unique risks associated with working remotely.
3 minutes
- 8
Storing passwords
A password is simply a secret word or phrase that is used to get access to something.
6 minutes
- 9
Locking Devices
When leaving any of your devices unattended, it’s crucial to make sure that you have locked or logged out of them.
4 minutes
- 10
Social Media handles
Social media virtually connects people around the world. But with all of this accessible information, it has become a playground for hackers to target us.
5 minutes
Need the full ADHICS compliance lifecycle — governance, risk, audit and training at enterprise scale? Explore GRSCIA →