SECURITY AWARENESS
Users of information systems must understand and support the need for information security or they will find ways to circumvent controls. This can create a very high risk in which it is believed that appropriate controls are in effect when in fact they are being subverted. A security awareness program is the vehicle for keeping users and management informed of the need to implement and practice the principles of a reasonable security. Through the application of time, resources and perseverance, the awareness of management and staff must be raised initially by intensive education and maintained through continual reinforcement of basic security principles as well as presentment of new risks and security controls.