Security Awareness Training
By AwareGO
The implementation process for AwareGO's Security Awareness Training is designed to be straightforward and efficient, allowing organizations to quickly integrate the platform into their existing systems. Here is a typical process outlined in steps:
Initial Setup and Assessment: The process begins with setting up the platform, which is cloud-based and integrates seamlessly with existing infrastructure through robust APIs and SCORM content. Organizations can start with a Human Risk Assessment to identify specific areas of vulnerability and tailor the training content accordingly.
Customization and Scheduling: Once the assessment is complete, organizations can customize the training programs to address their unique needs. This includes selecting relevant training modules from AwareGO's extensive library of content. Training can be scheduled over weeks, with notifications and reminders sent via email, Slack, or Teams to ensure consistent engagement.
Deployment and Integration: The training content is deployed using AwareGO's user-friendly management portal, which allows for easy scheduling and management of training sessions. The platform supports integration with tools like Active Directory and Google Workspace, facilitating smooth user management and content delivery.
Ongoing Engagement and Monitoring: AwareGO's platform includes automated features that suggest additional training based on individual employee performance. The training is delivered in engaging formats, such as short videos and quizzes, to maintain interest and reinforce learning. Progress is tracked through dashboards that provide insights into employee engagement and training effectiveness.
Review and Continuous Improvement: The final step involves regularly reviewing training performance and making necessary adjustments to the programs. AwareGO offers reporting and analytics tools to help organizations assess the impact of the training and identify areas for improvement.
Tailored Content: AwareGO offers over 100 original pieces of content, including interactive scenarios, videos, quizzes, whitepapers, and more. Organizations can select and tailor the training content to specific company departments or roles based on known threat areas from their Human Risk Assessment.
Localization: The training content is available in 18 languages, allowing organizations to deliver training in the preferred language of their employees.
Integration: The training can be integrated into existing communication channels like Slack, Teams, or email to fit the organization's workflows. The content is also available in SCORM standard to work with any existing LMS.
Custom Programs: Organizations can create custom training programs by adding their own content or policies to AwareGO's platform.
Free Trial: AwareGO provides a free trial of their security awareness training with access to free videos, allowing organizations to evaluate if the platform fits their needs before committing.
Ongoing Support: AwareGO mentions providing ongoing support, including resources and a dedicated helpdesk, to address any questions or concerns that may arise after training completion.
AwareGO implements both physical and technical security measures to protect customer data stored on their platform:
All data is protected by physical security measures that restrict access to AwareGO's facilities.
Technical measures like encryption and access controls are in place to restrict data access only to authorized personnel.
AwareGO continuously updates their training content library with over 100 original pieces like videos, scenarios, and digital nudges to keep it current with emerging threats.
Their content is created with inputs from a panel of 160 cybersecurity leaders who share techniques and experiences to keep the training relevant.
Being a cloud-based system, updates can likely be pushed out seamlessly to all customers without major disruptions.
Data Ownership
User Rights: Users have the right to be informed about the data stored concerning them, its origin, recipient, and the purpose of data processing. They can contact AwareGO's Data Protection Officer for this information.
Data Control: Users can object to the future processing of their data, withdraw consent for data use (e.g., for newsletters), and have the right to correct, delete, or limit the processing of their personal data. They also have the right to data transferability.
Data Portability
Data Transferability: Users have the right to data transferability, meaning they can request their personal data in a structured, commonly used, and machine-readable format. This allows them to transfer their data to another service provider if they choose.
Integration with Other Systems: AwareGO's platform supports integration with various systems such as LMS, SIEM, and MSSP platforms, which facilitates data portability and interoperability with other solutions.
Security Measures
Technical and Organizational Measures: AwareGO employs a variety of security measures to protect personal information, including physical, technical, and procedural measures. Data transmission is encrypted using SSL technology, and access to personal data is restricted to authorized personnel who are trained in security and privacy practices.
Compliance and Updates
GDPR Compliance: AwareGO handles all data processing procedures in accordance with GDPR provisions, ensuring that users' rights regarding data ownership and portability are protected.
Contract Renewal
Automatic Renewal: The subscription is automatically renewed every month or year, depending on the chosen Subscription Term.
Subscription Term: Users can select either a monthly or annual subscription term, which will determine the frequency of automatic renewals.
Cancellation
Cancellation Policy: Users can cancel their subscription at any time. However, the specific process for cancellation is not detailed in the provided sources.
Refund Policy: The terms mention a cancellation and refund policy, but specific details about refunds upon cancellation are not provided in the available sources.
Access to Content: Upon cancellation, users will lose access to the full range of subjects and content available through the subscription. Only two free subjects remain accessible without a subscription.
Additional Terms
Payment: Payment for the subscription is required to access the full range of subjects. The terms specify that payment will be processed to continue access to the content.
SOC 2: AwareGO's training program is designed to help organizations prepare for SOC 2 audits, which focus on the security, availability, processing integrity, confidentiality, and privacy of customer data.
ISO 27001: The training also prepares organizations for ISO 27001 audits, which is an international standard for information security management systems (ISMS).
GDPR: AwareGO offers training that helps organizations comply with the General Data Protection Regulation (GDPR), which is crucial for handling personal data of EU citizens.
PCI-DSS: The training meets the standards of the Payment Card Industry Data Security Standard (PCI-DSS), which is essential for organizations that handle credit card information.
HIPAA: Although not explicitly mentioned in the provided sources, security awareness training typically includes compliance with the Health Insurance Portability and Accountability Act (HIPAA), which is critical for organizations handling health information.
NIST 800-53: The training aligns with the National Institute of Standards and Technology (NIST) Special Publication 800-53, which provides a catalog of security and privacy controls for federal information systems and organizations.