A suspicious email can expose an organization to risk with one click. A misplaced access badge can create a security risk when it falls into the wrong hands. A weak password can give unauthorized users an opportunity to access sensitive information. When employees understand security policies and can recognize potential threats, they play an important role in strengthening an organization’s overall security posture. ASIS SA-2020, Security Awareness Standard offers guidance for creating and maintaining a security awareness program designed to reduce vulnerabilities, encourage responsible security-related actions, and promote a culture of security.
Importance of Security Awareness Training
Because human factor drives 60% to 74% of all successful cyber-attacks, structured security awareness education is a critical line of defense. Organizations with effective security awareness training programs are 8.3 times less likely to appear on public data breach lists.
An effective security awareness program drastically reduces human error, and ASIS SA-2020 provides general principles, guidance, and examples to help organizations develop and maintain security awareness as part of enterprise security risk management.
What Is ASIS SA-2020?
ASIS SA-2020 provides guidance to help organizations establish, implement, and communicate a security awareness program. It provides general principles, guidance, and examples to assist organizations in creating and maintaining an effective security awareness posture as part of an enterprise security risk management program.
What Is a Security Awareness Program?
ASIS SA-2020 defines a security awareness program as a “program to promote organizational and individual actions that can be taken to reduce vulnerabilities to risks and threats and promote a culture of security.”
This standard notes that an effective security awareness program provides a framework for awareness of and compliance with security policies/procedures, controls, and practices to assure organizations and individuals (e.g., employees and others working on behalf of the organization) act responsibly and make appropriate security-related decisions.
Creating a Culture of Security
One of the central ideas behind ASIS SA-2020 is the development of a culture of security. This notion refers to the set of organizational values that outlines how people are expected to think about and approach security, as well as the degree to which they embrace those values.
A security-conscious encourages individuals throughout an organization to understand why security practices matter and how their actions can affect organizational risk. For example, an employee who recognizes an unusual request for sensitive information, reports suspicious behavior, or follows established access procedures is actively contributing to the organization’s security posture.
Organizations can reinforce this culture by making security awareness relevant to employees’ responsibilities and by communicating expectations clearly and consistently.
What Can ASIS SA-2020 Help Organizations Achieve?
The framework in ASIS SA-2020 is applicable to organizations of all sizes and types, regardless of industry or sector (private/public) that wish to obtain:
- Top management support of awareness program objectives
- Guidance in understanding the role and importance of security policies and procedures, and promoting enterprise-wide compliance with those policies and procedures
- Recommendations for awareness, training, program content, and delivery methods
- Guidance to help influence or modify individual or collective attitudes and behaviors
- Guidance to help maintain, measure, evaluate, and continuously improve the security awareness program
ASIS SA-2020 is intended to be incorporated into an organization’s overall enterprise security risk management program to inform and promote its unique security culture.
Where to Find ASIS SA-2020
ASIS SA-2020, Security Awareness Standard is available on the ANSI Webstore, the best place to buy ASIS standards.
