Information Systems Awareness and Training
Blinn College Administrative Regulations Manual
Subject: Information Systems Awareness and Training
Effective Date: March 1, 2020; amended September 19, 2023
Board Policy Reference: CS
Purpose
Establish procedures and policies for employee and external account holders’ information security training.
Process
Training Policy and Procedures (AT-01)
Security awareness training must address the purpose, scope, roles, responsibilities and management commitment to secure use of information systems and is consistent with applicable laws, executive orders, directives, regulations, policies, standards and guidelines. Security awareness training shall be delivered in accordance with Texas Government Code § 2054.519 .
Employees and external account holders’ who use information resources must complete the required security awareness training as assigned by Human Resources.
Security Awareness Training (AT-02)
Blinn College District must provide an ongoing information security awareness education program for all users.
All new employees must complete security awareness training within 30 days of being granted access to information resources. External account holders’ must complete security awareness training before access is granted. Employees and external account holders’ must complete security awareness training on an annual basis.
Training must incorporate literacy on recognizing and reporting potential indicators of insider threats.
Role Based Security Training (AT-03)
Employees with assigned security roles must complete security training related to their security roles and responsibilities. The CISO must designate the training requirements as necessary. Human Resources will maintain records of completed security training.
Training Records (AT-4)
- Document and monitor information security and privacy training activities, including security and privacy awareness training and specific role-based security and privacy training; and
- Retain individual training records based on college document retention policies.