Skip to main content

๐Ÿ’ผ 2 An APRA-regulated entity would regularly educate users, including both internal staff and contractors, as to their responsibilities regarding securing information assets. Common areas covered would typically include:

  • Contextual name: ๐Ÿ’ผ 2 An APRA-regulated entity would regularly educate users, including both internal staff and contractors, as to their responsibilities regarding securing information assets. Common areas covered would typically include:
  • ID: /frameworks/apra-cpg-234/b/2
  • Located in: ๐Ÿ’ผ Attachment B - Training and awareness

Descriptionโ€‹

Empty...

Similarโ€‹

  • Internal
    • ID: dec-c-9ce8bc7d

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ a. personal versus corporate use of information assets;
๐Ÿ’ผ b. email usage, internet usage (including social networking) and malwareprotection;
๐Ÿ’ผ c. physical protection, remote computing and usage of mobile devices;
๐Ÿ’ผ d. awareness of common attack techniques targeted at personnel and facilities (e.g. social engineering, tailgating);
๐Ÿ’ผ e. access controls, including standards relating to passwords and other authentication requirements;
๐Ÿ’ผ f. responsibilities with respect to any end-user developed/configured software (including spreadsheets, databases and office automation);
๐Ÿ’ผ g. expectations of staff where bring-your-own-device is an option;
๐Ÿ’ผ h. handling of sensitive data;
๐Ÿ’ผ i. reporting of information security incidents and concerns.