Responsible Executive: Executive Vice President of Business and Finance
Responsible Officer: Chief Information Officer
PURPOSE
This policy establishes the guidelines for all employees to follow regarding Information Technology (IT) security awareness training.
Definitions
IT: Department of Information Technology
CISO: Chief Information Security Officer
Policy/Guideline
- Introduction
- The IT security awareness training provided and maintained by IT at Motlow State Community College (Motlow State) is intended to inform and educate all employees of their information security obligations, as well as reduce the risks associated with systems and data.
- Policy
- The CISO or designee, on behalf of Motlow State, shall define and ensure the implementation of the IT security awareness training and will determine any areas for improvement and associated risks.
- All new employees must complete their IT security awareness training within thirty (30) days of onboarding (start date).
- All employees must complete an annual IT security awareness training. The start date for the training will be determined by the CISO, and employees will have sixty (60) days to complete training.
- Employees changing roles within Motlow Sate may be required to complete role-based IT security awareness training, which may vary from general training, and will be determined by the CISO on a case-by-case basis.
- Additional trainings may be required as security challenges and changes arise. These
trainings will be determined by IT including but not limited to the following:
- Ransomware awareness training
- Email security training
- Data storage security training
- Authentication security training (i.e. passwords, MFA, etc)
- Compliance security training (i.e. GLBA, PCI, HIPAA, FERPA, etc)
- Violation of this Policy
- This policy is mandatory for all employees. Any and all violations of this policy shall be reported to the CISO or CIO immediately.
- IT is authorized to limit or completely disable any access to Motlow resources if
an employee is non-compliant with this policy.
- For new employees: If an employee is non-compliant after thirty (30) days of start date, then the employee supervisor will be notified and will need to clear (once training is complete) the employee before restoring access to Motlow resources.
- For all employees: If an employee is non-compliant with annual training requirements sixty (60) days after the training deadline, the employee's supervisor will be notified and will need to clear the employee once training is complete for access to Motlow State resources is restored.
- Disciplinary Procedures
- Allegations of violation to this policy shall be referred by the CISO or CIO to the appropriate person(s) for possible employee disciplinary action. Exceptions to this rule could be made via HR approval.
- Sanctions
- Persons violating this policy are subject to revocation or suspension of access privileges to Motlow State institutional IT resources.
- Sanctions for violation of this policy by employees may extend to termination of employment. Violations of law may be referred for criminal or civil action.
- Other sanctions may be appealed under established Institution procedures.
Sources
History
Proposed New Policy: May 26, 2026
IOC Approval: June 24, 2026
President’s Cabinet Approval: July 14, 2026
Policy Effective Date: July 14, 2026
