IT Security Awareness Training : 1:08:00:06

Responsible Executive: Executive Vice President of Business and Finance 

Responsible Officer:  Chief Information Officer 

PURPOSE

This policy establishes the guidelines for all employees to follow regarding Information Technology (IT) security awareness training. 

Definitions 

IT: Department of Information Technology 

CISO: Chief Information Security Officer 

Policy/Guideline 

  1. Introduction 
    1. The IT security awareness training provided and maintained by IT at Motlow State Community College (Motlow State) is intended to inform and educate all employees of their information security obligations, as well as reduce the risks associated with systems and data. 
  2. Policy 
    1. The CISO or designee, on behalf of Motlow State, shall define and ensure the implementation of the IT security awareness training and will determine any areas for improvement and associated risks. 
    2. All new employees must complete their IT security awareness training within thirty (30) days of onboarding (start date). 
    3. All employees must complete an annual IT security awareness training. The start date for the training will be determined by the CISO, and employees will have sixty (60) days to complete training. 
    4. Employees changing roles within Motlow Sate may be required to complete role-based IT security awareness training, which may vary from general training, and will be determined by the CISO on a case-by-case basis. 
    5. Additional trainings may be required as security challenges and changes arise. These trainings will be determined by IT including but not limited to the following: 
      1. Ransomware awareness training 
      2. Email security training 
      3. Data storage security training 
      4. Authentication security training (i.e. passwords, MFA, etc) 
      5. Compliance security training (i.e. GLBA, PCI, HIPAA, FERPA, etc) 
  3. Violation of this Policy    
    1. This policy is mandatory for all employees.  Any and all violations of this policy shall be reported to the CISO or CIO immediately. 
    2. IT is authorized to limit or completely disable any access to Motlow resources if an employee is non-compliant with this policy. 
      1. For new employees: If an employee is non-compliant after thirty (30) days of start date, then the employee supervisor will be notified and will need to clear (once training is complete) the employee before restoring access to Motlow resources. 
      2. For all employees: If an employee is non-compliant with annual training requirements sixty (60) days after the training deadline, the employee's supervisor will be notified and will need to clear the employee once training is complete for access to Motlow State resources is restored. 
    3. Disciplinary Procedures   
      1. Allegations of violation to this policy shall be referred by the CISO or CIO to the appropriate person(s) for possible employee disciplinary action. Exceptions to this rule could be made via HR approval.  
    4. Sanctions 
      1. Persons violating this policy are subject to revocation or suspension of access privileges to Motlow State institutional IT resources. 
      2. Sanctions for violation of this policy by employees may extend to termination of employment. Violations of law may be referred for criminal or civil action. 
      3. Other sanctions may be appealed under established Institution procedures. 

Sources

History

Proposed New Policy: May 26, 2026  

IOC Approval:  June 24, 2026 

President’s Cabinet Approval: July 14, 2026 

Policy Effective Date: July 14, 2026