Last reviewed: December 2017
|
More than 200 colleges and universities joined EDUCAUSE, Internet2, and the REN-ISAC to show their support as official NCSAM champions in 2017. Champion registration for 2018 will be available on the National Cyber Security Alliance website in May. |
The Oxford English Dictionary defines awareness as "The quality or state of being aware; consciousness." Aware is defined as "Informed; cognizant; conscious; sensible."
The purpose of cyber security awareness presentations is simply to focus attention on cyber security. Awareness presentations are intended to allow individuals to recognize information technology security concerns and respond accordingly.
We can characterize a user's cyber security awareness level by describing it as the actions a user takes in a given security situation. Do they know about any policies governing that activity? Do they follow the policy? What happens when they are confronted by a new situation that is not addressed by the policy?
To protect the confidentiality, integrity, and availability of information in today's highly networked systems environment requires that all individuals:
Cyber security awareness programs impress upon users the importance of cyber security and the adverse consequences of its failure. Awareness may reinforce knowledge already gained, but its goal is to produce security behaviors that are automatic. The goal is to make "thinking security" a natural reflex for everyone in the organization. Awareness activities can build in these reflexes both for the security professional and for the everyday user.
Awareness programs usually use repetition to reinforce desired behaviors and attitudes about security.
National Cyber Security Awareness Month is an annual effort to increase awareness and prevention of online security problems, spearheaded by the U.S. Department of Homeland Security and the National Cyber Security Alliance (NCSA). The Higher Education Information Security Council (HEISC) promotes and participates in the annual campaign each October, joining forces with a range of organizations from the public and private sector to expand cybersecurity awareness on campuses across the country. HEISC offers many resources made by and for information security professionals in higher education.
The following NCSAM Planning Guide worksheet (PDF or Word) will help you to think about how your institution might go about implementing a plan to take advantage of National Cyber Security Awareness Month. You can also use the Annual Campus Security Awareness Campaign, which includes monthly security awareness topics and 12 blog posts on the monthly topics with ready-made content for your campus communication channels.
Texas A&M University tries to create cybersecurity awareness campaigns that engage students in security education. For six years, they have created awareness campaigns featuring online cybersecurity games that entice more than 10,000 campus members to participate and that number continues to grow each year. Learn more about their planning process by reading their May 2017 guest blog: Bridging the Gap Between Students and Security: 7 Steps to Creating a Successful Cybersecurity Campaign.
The winning posters and videos from previous Information Security Awareness Video & Poster Contests are available for use in campus security awareness campaigns during student orientation, National Cyber Security Awareness Month, Data Privacy Day, and throughout the year.
Note: Videos are also available to view on the HEISC YouTube Channel. Posters can be found on the HEISC Facebook page or Pinterest page.
If your group or institution would be interested in a presentation from an information security or privacy expert, please see our Speakers Bureau. You could also use your LinkedIn connections to invite a local, regional, or national speaker to a campus event.
Note: Data Privacy Day occurs each year on January 28. Think about how you might use NCSAM resources to promote this international celebration on your campus, too.
Questions or comments? Contact us.
Except where otherwise noted, this work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License (CC BY-NC-SA 4.0).