10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

provided to all users responsible for the administration and maintenance <strong>of</strong> a<br />

system:<br />

3.2.2.a Positional Roles Requiring Security Operations Training<br />

• The following roles types, at a minimum, require security<br />

operations training:<br />

o Roles with application implementation and/or<br />

administration responsibilities.<br />

o Roles with server implementation and/or<br />

administration responsibilities.<br />

o Roles with desktop/laptop implementation and/or<br />

administration responsibilities.<br />

o Roles with network infrastructure implementation<br />

and/or administration responsibilities.<br />

o Roles with storage infrastructure implementation<br />

and/or administration responsibilities.<br />

o Roles with security infrastructure implementation<br />

and/or administration responsibilities.<br />

3.2.2.b Security Operations Training Frequency and Scheduling<br />

• Security operations training shall be provided for all<br />

employees with security operations responsibilities within 90<br />

days <strong>of</strong> commencement <strong>of</strong> employment.<br />

• Security operations training shall be provided for all<br />

employees with security operations responsibilities within 90<br />

days <strong>of</strong> the deployment <strong>of</strong> a new or significantly revised<br />

system. Where possible, employees will be trained together as<br />

groups.<br />

• Security operations training shall be provided thereafter for all<br />

employees with security responsibilities on an at least annual<br />

basis. Where possible, employees will be trained together as<br />

groups.<br />

3.3. Maintain Records<br />

Capture documentation appropriate to all training processes:<br />

• Document and retain copies <strong>of</strong> employee completion <strong>of</strong> security awareness<br />

training.<br />

• Document and retain copies <strong>of</strong> employee completion <strong>of</strong> security operations<br />

training.<br />

Mandatory Baselines<br />

Page 6 <strong>of</strong> 25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!