Essential Cybersecurity Controls (ECC – 2 : 2024) - 1-10-1
A Cybersecurity Awareness Program Must Be Developed And Approved. The Program Must Be
Conducted Periodically Through Multiple Channels To Strengthen The Awareness About Cybersecurity,
Cyber Threats And Risks, And To Build A Positive Cybersecurity Awareness Culture.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 1-10-2
The Cybersecurity Awareness Program Must Be Implemented.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 1-10-3
- The cybersecurity awareness program must cover the latest cyber threats and how to protect against them, and must include at least the following subjects:
- Secure handling of email services, especially phishing emails.
- Secure handling of mobile devices and storage media.
- Secure Internet browsing.
- Secure use of social media.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 1-10-4
- Essential and customized (i.e., tailored to job functions as it relates to cybersecurity) training and access to professional skillsets must be made available to personnel working directly on tasks related to cybersecurity including:
- Cybersecurity function’s personnel.
- Personnel working on software/application development. and information and technology assets operations.
- Executive and supervisory positions.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 1-10-5
The Implementation Of The Cybersecurity Awareness Program Must Be Reviewed Periodically