Âé¶¹ÆÆ½â°æ

Skip to main content
Close menu Âé¶¹ÆÆ½â°æ

Information Security Training Policy

Purpose

The purpose of this Information Security Training Policy is to require that people in defined roles participate in mandatory information security training annually.

Scope

This policy applies to Âé¶¹ÆÆ½â°æ as a whole university, including the Virginia Institute of Marine Science (VIMS) and all active faculty, staff, affiliates, and retired faculty with active email accounts.

Initial Training

All new employees will undergo mandatory information security training within the first 90 days of their work start date.  The initial training will include an overview of Âé¶¹ÆÆ½â°æ’s Information Security Policies, general information security concepts and best practices, and topic specific training focused on current or emerging threats.

Ongoing Annual Training

All active faculty, staff, affiliates, and retired faculty with active email accounts will also be assigned information security training once a year.  Failure to complete required training will result in suspension of IT services.  In addition, the W&M Information Security Office will administer a simulated phishing campaign throughout the year focused on all active faculty, staff, affiliates and students.

Role Based Training

  • Individuals working with credit card transactions at the university are required to attend annual PCI DSS training in addition to the general annual training.
  • University departments working with sensitive data must meet with the Chief Information Security Officer annually to assess risks to the sensitive data and the effectiveness of controls in place to mitigate those risks.
  • Individuals working with data covered by the Graham Leach Bliley Act are required to attend annual GLBA training in addition to the general annual training.
  • All members of the Information Security Team are required to participate in some form of professional development activity annually.

Exemptions

Requests for exemptions from this policy must be submitted to and approved by the Chief Information Security Officer. 

Non-compliance

Failure to comply with this policy may result in suspension of IT services and further disciplinary action.