Security Awareness Policy
Purpose and Scope
This policy ensures that all users of Howard Community College (HCC) Information Technology (IT) systems receive appropriate information security awareness and role-based training. It applies to all faculty, staff, contractors, and users of HCC IT resources. The purpose is to reduce security risks by educating users on best practices, expected behaviors, and threat recognition in alignment with industry standards.
This policy references guidance from the National Institute of Standards and Technology (NIST) including SP 800-53, SP 800-12, SP 800-16, SP 800-50, and SP 800-100; Center for Internet Security (CIS) Critical Controls v8; and 5 CFR 930.301.
Responsibilities
Chief Information Officer (CIO)
- Oversees this policy and ensures its alignment with institutional and regulatory requirements.
Information Security
- Coordinates the development and implementation of training content and schedule.
- Reviews and approves exception requests in consultation with the CIO.
- Delivers security training content.
- Maintains training records.
- Evaluates and updates training based on changes to systems, threats, or policy.
- Report training records to appropriate auditing agencies.
Department Heads and Supervisors
- Ensure staff complete required security training.
- Support the integration of security awareness into departmental operations.
End Users
- Complete assigned security training in a timely manner.
- Report suspicious activity as instructed during training.
Policy
1. Security Awareness Training
HCC shall:
- Deliver training to all new users during onboarding (Access and Responsibility).
- Require training regularly on a schedule deemed appropriate by the CIO, or as necessitated by major system changes.
- Offer training content based on user role, system access, and evolving threats.
Training will include:
- Understanding the importance of information security.
- How to identify and report potential incidents.
- Operational security awareness through various methods (e.g., posters, screen messages, events).
2. Insider Threat Awareness
The IT Department will incorporate training on identifying and reporting insider threat indicators as part of ongoing security awareness efforts.
3. Role-Based Security Training
Personnel assigned security-sensitive roles shall receive:
- Initial training before system access is granted.
- Periodic refresher training or upon system changes.
Training includes instruction on environmental and physical security controls such as fire suppression systems, HVAC, and power infrastructure.
4. Physical Security Controls
Personnel responsible for facility access and safety systems shall receive training on:
- Use and maintenance of physical security technologies (e.g., alarms, access controls, surveillance systems).
- Procedures for responding to physical security threats.
5. Practical Exercises
The IT Department shall implement practical exercises to reinforce training.
Examples include:
- Simulated phishing attacks.
- Tabletop scenarios for staff and leadership.
Compliance
Employees who fail to comply with this policy may face disciplinary actions up to and including termination, and may be subject to civil and criminal penalties. Contractors or third-party users violating this policy may have contracts terminated and access revoked and may be subject to civil and criminal penalties.
Policy Exceptions
Exception requests must be submitted in writing to the CIO. The request must include:
- Scope and justification
- Associated risks and mitigations
- Timeline to achieve compliance
The CIO, in consultation with relevant departments, will review and determine the outcome.
Responsible Department
Information Security
Effective Date: September 17, 2026
Approved By: Senior Leadership Team