Environmental Protection Agency Design Document
Business Purpose | Cybersecurity is a critical concern for any organization or individual using digital technology. Cyber threats are increasing in sophistication and frequency, and it's crucial to adopt basic cybersecurity protocols to mitigate potential risks. There has been a 30% increase in employees clicking on malicious links. Additionally, there has been an observed number of unattended computers that have not been locked down while the employee is away from his or her desk. Over time, employees have been negligent of cybersecurity which caused loss of data (PII, SPII, CUI). This training will provide a mid-year refresher course on basic cybersecurity protocols and the importance of being vigilant. The goal would be to identify, respond to, and report security incidents within the Computer Security Incident Response Capability (CSIRC). | |
Target Audience | The audience is all EPA employees, contractors, and all other users of EPA information and information systems that support the operations and assets of the EPA. | |
Training Time | 45 Minutes | |
Training Recommendation | Based on federal requirements and mandates, the EPA is responsible for ensuring all offices within the Agency meet the minimum-security requirements. Overall, e-learning provides an effective and efficient way to deliver cybersecurity training that is accessible, cost-effective, and scalable. It allows users to learn at their own pace and provides a consistent, interactive, and measurable training experience. | |
Deliverables |
| |
Learning Objectives | By the end of the training, the learners will be able to…
| |
Training Outline | Introduction
Topic: Privacy Basics
Any security situation that could compromise X information or information systems (e.g., virus, phishing emails, social engineering attack).
Topic: Response & Reporting
The scene will show an employee panicking due to a computer being hacked. A coworker comes in to guide her through the appropriate steps to responding and reporting the system hack. Summary
Assessment The assessment may include a variety of question types, such as multiple-choice, true/false, and scenario-based questions. The questions will cover a range of topics referencing the learning objectives. The eLearning cybersecurity assessment may also provide feedback on areas where the individual may need to improve their cybersecurity knowledge. This can help organizations identify knowledge gaps and develop targeted training programs to improve the cybersecurity awareness of their employees. Congratulations | |
Assessment Plan | 80% passing on e-learning module assessment of Incident Response & Reporting via 5 multiple-choice questions. | |
Information Security —Design Document - Page of