2602.0—2602.0
>Control Description
The Supplier shall ensure that people who support the operation of Functions and protection of Data are appropriately trained in cyber security. The Supplier shall conduct awareness training at least every 12 months to recognise and respond to the following topics:
i) Social engineering and phishing
ii) Advanced persistent threats
iii) Suspected breaches
iv) Suspicious behaviours.
A range of approaches to cyber security training, awareness and communications shall be employed and the Supplier shall update the training every 12 months or when there are significant changes to the threat.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.