S 3.77 Awareness-raising for secure Internet use

Initiation responsibility: Supervisor, Head of Personnel, IT Security Officer

Implementation responsibility: Personnel Department, IT Security Officer

In companies or government agencies, the Internet can be used for a variety of purposes and via various services. This includes, for example, communication with customers via e-mail, instant messaging, discussion forums or blogs, the representation of the organisation via its own websites or information searches. To be able to use the Internet securely from the organisation's point of view, the use of certain services or sites can be prohibited or restricted. As it is not possible to prevent the use of all undesired services by technical means, among others reasons, because new offers and services are constantly introduced, it makes more sense to train the users in the secure and reasonable use of the Internet. This also includes informing the employees on how they can avoid leaving undesired traces of data during Internet use through correct behaviour and optimal configuration of the Internet applications such as the browser.

The employees must be made aware of potential threats and security safeguards to be followed during Internet use. In particular, they should be informed of the following:

A one-off instruction on the secure use of the Internet is not sufficient. Instead, the employees should be continuously informed of the latest developments. In addition to traditional training, web-based interactive programs and information in the intranet could also be considered for this purpose. Current developments may also be communicated with the help of newsletters or circular letters and within the framework of regular events such as department meetings.

Review questions: