As per Section 4-5, paragraph a.(8)(a):
All users must receive IA awareness training tailored to the system and information accessible before issuance of a passWord for network access. The training will include the following:
- Threats, vulnerabilities, and risks associated with the system. This portion will include specific information regarding measures to reduce malicious logic threats, principles of shared risk, external and internal threat concerns, acceptable use, privacy issues, prohibitions on loading unauthorized software or hardware devices, and the requirement for frequent backups.
- Information security objectives (that is, what needs to be protected).
- Responsibilities and accountability associated with IA.
- Information accessibility, handling, and storage considerations.
- Physical and environmental considerations necessary to protect the system.
- System data and access controls.
- Emergency and disaster plans.
- Authorized systems configuration and associated CM requirements.
- Incident, intrusion, malicious logic, virus, abnormal program, or system response reporting requirements.
- INFOCON requirements and definitions.
- AUP requirements.