Security awareness training is often the first view a typical user has into information security. Its often required for all new hires. Think of it as the first impression of managements view of information security. This is managements opportunity to set the tone. Most individuals want to do a good job, but they need to know what the rules and expected behavior are. That is one of the purposes of a security awareness policy.

Answer the following question(s):

  1. What do you think are the two most important practices that should be incorporated into a security awareness policy?
  2. Why do you rank them so highly?

Fully address the questions in this discussion; provide valid rationale for your choices, where applicable; and respond to at least two other students views

