This document is under active development and has not been finalized.
Skip to content

Awareness & Cyber Hygiene

Awareness Program

Ongoing Measures

MeasureDescriptionInterval
Phishing simulationRealistic phishing emails sent to all employeesSemi-annually
Security advisoriesCurrent warnings for relevant threats (e.g., new phishing wave)Event-driven
Onboarding briefingSecurity induction for new employeesUpon joining
Annual mandatory trainingRefresher on all basic topicsAnnually

Phishing Simulation

AspectDescription
Frequency2x per year
Difficulty levelVaries (basic to advanced)
EvaluationClick rate, report rate, department comparison
Remedial trainingAutomatic for employees who clicked
Target click rate< 5%

Cyber Hygiene Rules

Workplace

RuleDescription
Screen lockAutomatic after 5 minutes of inactivity
Clean deskNo confidential documents left in the open
Removable mediaUSB drives only with IT approval
Personal devicesNo access to corporate data from personal devices without MDM

Passwords & Authentication

RuleDescription
Password managerMandatory for all employees
Unique passwordsEach service receives its own password
MFAEnabled for all external services and admin access
Password sharingProhibited -- access only via personalized accounts

Communication

RuleDescription
Suspicious emailsDo not open, do not forward, report to ISO
Confidential dataTransmit only via encrypted channels
Public networksUse only with VPN
Unknown callersNever disclose credentials or internal information

Documentation

EvidenceDescriptionRetention
Training completionAttendance confirmation per moduleMinimum 3 years
Phishing resultsAggregated statistics per campaign2 years
Onboarding confirmationSigned security policy acknowledgmentDuration of employment

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT